PT-2023-5873 · Libcue+6 · Libcue+6

Kevinbackhouse

·

Published

2023-10-09

·

Updated

2024-07-31

·

CVE-2023-43641

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libcue versions 2.2.1 and prior
Description The issue is related to out-of-bounds array access in libcue, which provides an API for parsing and extracting data from CUE sheets. A user of the GNOME desktop environment can be exploited by downloading a cue sheet from a malicious webpage. Because the file is saved to ~/Downloads, it is then automatically scanned by tracker-miners, and since it has a .cue filename extension, tracker-miners use libcue to parse the file, allowing the file to exploit the vulnerability in libcue to gain code execution.
Recommendations For versions 2.2.1 and prior, update to version 2.3.0 to resolve the issue. As a temporary workaround, consider disabling the use of libcue for parsing .cue files until a patch is available. Restrict access to the tracker-miners to minimize the risk of exploitation. Avoid downloading and opening cue sheets from untrusted sources.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2023-6257
ALT-PU-2023-6273
ALT-PU-2023-6613
BDU:2023-06566
CVE-2023-43641
DLA-3615-1
DSA-5524-1
GHSA-5982-X7HV-R9CJ
MGASA-2023-0300
OESA-2023-1743
OESA-2023-1744
OESA-2023-1745
OPENSUSE-SU-2024:13319-1
SUSE-SU-2023:4090-1
SUSE-SU-2023_4090-1
USN-6423-1
USN-6423-2

Affected Products

Alt Linux
Astra Linux
Linuxmint
Red Os
Suse
Ubuntu
Libcue