CVE-2023-43641 is a critical out-of-bounds array access vulnerability in libcue versions 2.2.1 and earlier, primarily affecting GNOME desktop environments and various Linux distributions. This flaw allows for remote code execution (RCE) with a single click, as a malicious CUE sheet downloaded to ~/Downloads is automatically parsed by tracker-miners. With a CVSS score of 8.8 (HIGH) and an EPSS score indicating high exploitability, the vulnerability presents a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While there is no public exploit code or active exploitation reported, the vulnerability has garnered substantial community discussion and media coverage, highlighting its potential for widespread impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.0CPE matchmatch criteria | cpe:2.3:a:lipnitsk:libcue:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.