Lipnitsk Libcue 2.2.1

CPE Details

Lipnitsk Libcue 2.2.1
2.2.1
2023-10-25
14h53 +00:00
2023-10-25
14h53 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:lipnitsk:libcue:2.2.1:*:*:*:*:*:*:*

Informations

Vendor

lipnitsk

Product

libcue

Version

2.2.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-43641 2023-10-09 21h01 +00:00 libcue provides an API for parsing and extracting data from CUE sheets. Versions 2.2.1 and prior are vulnerable to out-of-bounds array access. A user of the GNOME desktop environment can be exploited by downloading a cue sheet from a malicious webpage. Because the file is saved to `~/Downloads`, it is then automatically scanned by tracker-miners. And because it has a .cue filename extension, tracker-miners use libcue to parse the file. The file exploits the vulnerability in libcue to gain code execution. This issue is patched in version 2.3.0.
8.8
High