CVE-2023-43641 Details
Description
libcue provides an API for parsing and extracting data from CUE sheets. Versions 2.2.1 and prior are vulnerable to out-of-bounds array access. A user of the GNOME desktop environment can be exploited by downloading a cue sheet from a malicious webpage. Because the file is saved to `~/Downloads`, it is then automatically scanned by tracker-miners. And because it has a .cue filename extension, tracker-miners use libcue to parse the file. The file exploits the vulnerability in libcue to gain code execution. This issue is patched in version 2.3.0.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 14, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lipnitsk libcue | < 2.3.0 |
CPE
Remediation
| |
| fedoraproject fedora | 37 38 39 |
CPE
Remediation
| |
| debian debian linux | 10.0 11.0 12.0 |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 9, 2023 | CVE Modified | [email protected] |
| Oct 27, 2023 | Initial Analysis | [email protected] |
| Oct 13, 2023 | CVE Modified | [email protected] |
| Oct 12, 2023 | CVE Modified | [email protected] |
| Oct 12, 2023 | CVE Modified | [email protected] |
| Oct 12, 2023 | CVE Modified | [email protected] |
| Oct 11, 2023 | CVE Modified | [email protected] |
| Oct 11, 2023 | CVE Modified | [email protected] |
| Oct 11, 2023 | CVE Modified | [email protected] |
| Oct 11, 2023 | CVE Modified | [email protected] |
| Oct 10, 2023 | CVE Modified | [email protected] |
| Oct 10, 2023 | CVE Modified | [email protected] |