Security News > 2023 > October > GNOME Linux systems exposed to RCE attacks via file downloads

GNOME Linux systems exposed to RCE attacks via file downloads
2023-10-09 20:24

A memory corruption vulnerability in the open-source libcue library can let attackers execute arbitrary code on Linux systems running the GNOME desktop environment.

Libcue, a library designed for parsing cue sheet files, is integrated into the Tracker Miners file metadata indexer, which is included by default in the latest GNOME versions.

GNOME is a widely used desktop environment across various Linux distributions such as Debian, Ubuntu, Fedora, Red Hat Enterprise, and SUSE Linux Enterprise.

Attackers can successfully exploit the flaw in question to execute malicious code by taking advantage of Tracker Miners automatically indexing all downloaded files to update the search index on GNOME Linux devices.

While successful exploitation of CVE-2023-43641 requires tricking a potential victim into downloading a.cue file, ​admins are advised to patch systems and mitigate the risks posed by this security flaw, as it provides code execution on devices running the latest releases of widely used Linux distros, including Debian, Fedora, and Ubuntu.

Backhouse has found other severe Linux security flaws in recent years, including a privilege escalation bug in the GNOME Display Manager and an authentication bypass in the polkit auth system service installed by default on many modern Linux platforms.


News URL

https://www.bleepingcomputer.com/news/security/gnome-linux-systems-exposed-to-rce-attacks-via-file-downloads/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-10-09 CVE-2023-43641 Out-of-bounds Write vulnerability in multiple products
libcue provides an API for parsing and extracting data from CUE sheets.
network
low complexity
lipnitsk fedoraproject debian CWE-787
8.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Linux 11 64 2312 1489 67 3932
Gnome 56 5 65 74 15 159