{"id":1191284,"date":"2023-10-11T16:04:35","date_gmt":"2023-10-11T20:04:35","guid":{"rendered":"https:\/\/www.prime-wow.com\/?p=1191284"},"modified":"2023-10-11T16:04:35","modified_gmt":"2023-10-11T20:04:35","slug":"cd-indexing-cue-files-are-the-core-of-a-serious-linux-remote-code-exploit","status":"publish","type":"post","link":"https:\/\/www.prime-wow.com\/?p=1191284","title":{"rendered":"CD-indexing cue files are the core of a serious Linux remote code exploit"},"content":{"rendered":"<div id=\"rss-wrap\">\n<figure class=\"intro-image intro-left\">\n  <img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2023\/10\/GettyImages-130877670-800x535-1.jpg\" alt=\"Blank CD inserted into a laptop CD drive, with a spindle of blank CDs nearby.\" \/><\/p>\n<p class=\"caption\" style=\"font-size:0.8em\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/10\/GettyImages-130877670-scaled.jpg\" class=\"enlarge-link\" data-height=\"1713\" data-width=\"2560\">Enlarge<\/a> <span class=\"sep\">\/<\/span> Cue files used to be much better-known, back when we all used CD-Rs to make legal backup copies of material that we owned outright. (credit: Getty Images)<\/p>\n<\/figure>\n<div><a name=\"page-1\" \/><\/div>\n<p>It has been a very long time since the average computer user thought about <a href=\"https:\/\/en.wikipedia.org\/wiki\/Cue_sheet_(computing)\">.cue files<\/a>, or cue sheets, the metadata bits that describe the tracks of an optical disc, like a CD or DVD. But cue sheets are getting attention again, for all the wrong reasons. They&#8217;re at the heart of a one-click exploit that could give an attacker code execution on Linux systems with GNOME desktops.<\/p>\n<p><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-43641\">CVE-2023-43641<\/a>, <a href=\"https:\/\/github.blog\/2023-10-09-coordinated-disclosure-1-click-rce-on-gnome-cve-2023-43641\/#fn-74613-1\">disclosed by GitHub on October 9<\/a>, is a memory corruption (or out-of-bounds array writing) issue in the <a href=\"https:\/\/github.com\/lipnitsk\/libcue\">libcue library<\/a>, which parses cue sheets. NIST has yet to provide a score for the issue, but GitHub&#8217;s submission rates it an 8.8, or &#8220;High.&#8221; While the vulnerability has been patched in the core library, Linux distributions will need to update their desktops to fix it.<\/p>\n<p>GNOME desktops have, by default, a &#8220;tracker miner&#8221; that automatically updates whenever certain file locations in a user&#8217;s home directory are changed. If a user was compelled to download a cue sheet that took advantage of libcue&#8217;s vulnerability, GNOME&#8217;s indexing tracker would read the cue sheet, and code in that sheet could be executed.<\/p>\n<\/div>\n<p><a href=\"https:\/\/arstechnica.com\/?p=1975395#p3\">Read 5 remaining paragraphs<\/a> | <a href=\"https:\/\/arstechnica.com\/?p=1975395&amp;comments=1\">Comments<\/a><\/p>\n<p>&#013;<br \/>\n&#013;<br \/>\nSource: Ars Technica &#8211; <a href=\"https:\/\/arstechnica.com\/?p=1975395\" target=\"_blank\" rel=\"noopener\">CD-indexing cue files are the core of a serious Linux remote code exploit<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Enlarge \/ Cue files used to be much better-known, back when we all used CD-Rs to make legal backup copies of material that we owned outright. (credit: Getty Images) It has been a very long time since the average computer &hellip; <a href=\"https:\/\/www.prime-wow.com\/?p=1191284\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":1191285,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27,110],"tags":[73],"class_list":["post-1191284","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ars-technica","category-unfiltered-rss","tag-ars-technica"],"_links":{"self":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1191284","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1191284"}],"version-history":[{"count":0,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1191284\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/media\/1191285"}],"wp:attachment":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1191284"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1191284"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1191284"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}