Vulnerabilities > CVE-2023-5557
Attack vector
LOCAL Attack complexity
HIGH Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.
Vulnerable Configurations
References
- https://access.redhat.com/security/cve/CVE-2023-5557
- https://bugzilla.redhat.com/show_bug.cgi?id=2243096
- https://access.redhat.com/errata/RHSA-2023:7712
- https://access.redhat.com/errata/RHSA-2023:7713
- https://access.redhat.com/errata/RHSA-2023:7730
- https://access.redhat.com/errata/RHSA-2023:7731
- https://access.redhat.com/errata/RHSA-2023:7732
- https://access.redhat.com/errata/RHSA-2023:7733
- https://access.redhat.com/errata/RHSA-2023:7739
- https://access.redhat.com/errata/RHSA-2023:7744