Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-5557

Опубликовано: 26 сент. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.

Отчет

Red Hat Enterprise Linux 7 is not affected as the tracker sandbox is not available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7tracker-minersNot affected
Red Hat Enterprise Linux 8tracker-minersFixedRHSA-2023:773212.12.2023
Red Hat Enterprise Linux 8.2 Advanced Update Supporttracker-minersFixedRHSA-2023:773112.12.2023
Red Hat Enterprise Linux 8.2 Telecommunications Update Servicetracker-minersFixedRHSA-2023:773112.12.2023
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutionstracker-minersFixedRHSA-2023:773112.12.2023
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supporttracker-minersFixedRHSA-2023:773912.12.2023
Red Hat Enterprise Linux 8.4 Telecommunications Update Servicetracker-minersFixedRHSA-2023:773912.12.2023
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutionstracker-minersFixedRHSA-2023:773912.12.2023
Red Hat Enterprise Linux 8.6 Extended Update Supporttracker-minersFixedRHSA-2023:773312.12.2023
Red Hat Enterprise Linux 8.8 Extended Update Supporttracker-minersFixedRHSA-2023:773012.12.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-693

EPSS

Процентиль: 16%
0.00053
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.

CVSS3: 7.5
nvd
почти 2 года назад

A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.

CVSS3: 7.5
debian
почти 2 года назад

A flaw was found in the tracker-miners package. A weakness in the sand ...

suse-cvrf
больше 1 года назад

Security update for tracker-miners

rocky
больше 1 года назад

Important: tracker-miners security update

EPSS

Процентиль: 16%
0.00053
Низкий

7.5 High

CVSS3