Vulnerability Description
Creeper is an experimental dynamic, interpreted language. The binary release of Creeper Interpreter 1.1.3 contains potential malware. The compromised binary release was available for a few hours between December 26, 2020 at 3:22 PM EST to December 26, 2020 at 11:00 PM EST. If you used the source code, you are **NOT** affected. This only affects the binary releases. The binary of unknown quality has been removed from the release. If you have downloaded the binary, please delete it and run a reputable antivirus scanner to ensure that your computer is clean.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chatter-Social | Creeper | 1.1.3 |
Related Weaknesses (CWE)
References
- https://github.com/chatter-social/Creeper/security/advisories/GHSA-9v67-g2rg-m33Third Party Advisory
- https://github.com/chatter-social/Creeper/security/advisories/GHSA-9v67-g2rg-m33Third Party Advisory
FAQ
What is CVE-2020-26292?
CVE-2020-26292 is a vulnerability with a CVSS score of 3.1 (LOW). Creeper is an experimental dynamic, interpreted language. The binary release of Creeper Interpreter 1.1.3 contains potential malware. The compromised binary release was available for a few hours betwe...
How severe is CVE-2020-26292?
CVE-2020-26292 has been rated LOW with a CVSS base score of 3.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-26292?
Check the references section above for vendor advisories and patch information. Affected products include: Chatter-Social Creeper.