CVE-2023-43641: libcue vulnerable to out-of-bounds array access
libcue provides an API for parsing and extracting data from CUE sheets. Versions 2.2.1 and prior are vulnerable to out-of-bounds array access. A user of the GNOME desktop environment can be exploited by downloading a cue sheet from a malicious webpage. Because the file is saved to ~/Downloads, it is then automatically scanned by tracker-miners. And because it has a .cue filename extension, tracker-miners use libcue to parse the file. The file exploits the vulnerability in libcue to gain code execution. This issue is patched in version 2.3.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-43641?
CVE-2023-43641 is a vulnerability in libcue 2.2.1 and prior that allows for out-of-bounds array access.
How does CVE-2023-43641 affect users?
Users of the GNOME desktop environment can be exploited by downloading a cue sheet from a malicious webpage.
What is the severity of CVE-2023-43641?
The severity of CVE-2023-43641 is rated as high with a CVSS score of 8.8.
Which versions of libcue are affected by CVE-2023-43641?
Versions 2.2.1 and prior of libcue are affected by CVE-2023-43641.
How can CVE-2023-43641 be fixed?
To fix CVE-2023-43641, users should update to version 2.2.1-2ubuntu0.1 or later of libcue.