OESA-2023-1745
Dashboard / Vulnerabilities / OESA-2023-1745
Summary: libcue security update
Details: Libcue is intended for parsing a so-called cue sheet from a char string or a file pointer. For handling of the parsed data a convenient API is available. Security Fix(es): libcue provides an API for parsing and extracting data from CUE sheets. Versions 2.2.1 and prior are vulnerable to out-of-bounds array access. A user of the GNOME desktop environment can be exploited by downloading a cue sheet from a malicious webpage. Because the file is saved to `~/Downloads`, it is then automatically scanned by tracker-miners. And because it has a .cue filename extension, tracker-miners use libcue to parse the file. The file exploits the vulnerability in libcue to gain code execution. This issue is patched in version 2.3.0.(CVE-2023-43641)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1745, https://nvd.nist.gov/vuln/detail/CVE-2023-43641
Affected packages
Package
Name: libcue
Purl: pkg:rpm/openEuler/libcue&distro=openEuler-22.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
