Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-5557

Опубликовано: 13 окт. 2023
Источник: debian
EPSS Низкий

Описание

A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tracker-minersfixed3.4.5-1package
tracker-minersno-dsabookwormpackage
tracker-minersno-dsabullseyepackage
tracker-minersno-dsabusterpackage

Примечания

  • https://github.blog/2023-10-09-coordinated-disclosure-1-click-rce-on-gnome-cve-2023-43641/#tracker-miners-seccomp-sandbox-escape

  • https://gitlab.gnome.org/GNOME/tracker-miners/-/issues/277

  • https://gitlab.gnome.org/GNOME/tracker-miners/-/merge_requests/480

EPSS

Процентиль: 16%
0.00053
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.

CVSS3: 7.5
redhat
почти 2 года назад

A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.

CVSS3: 7.5
nvd
почти 2 года назад

A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.

suse-cvrf
больше 1 года назад

Security update for tracker-miners

rocky
больше 1 года назад

Important: tracker-miners security update

EPSS

Процентиль: 16%
0.00053
Низкий