PT-2024-13455 · Pure Data · Pure Data

Jeffbencteux

·

Published

2024-09-20

·

Updated

2024-09-26

·

CVE-2023-47480

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pure Data versions 0.54-0
Description An issue in Pure Data allows a local attacker to escalate privileges via the set*id() function. This is a local privilege escalation issue that can be exploited by a local attacker to gain higher privileges.
Recommendations For Pure Data version 0.54-0, update to version 0.54-1 to resolve the issue. As a temporary workaround, consider restricting the use of the set*id() function until a patch is available.

Fix

Unchecked Return Value

Weakness Enumeration

Related Identifiers

CVE-2023-47480
DLA-3895-1

Affected Products

Pure Data