Sunday, December 10, 2023
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

libcue vulnerability opens security leak in Gnome

Eliza Houghton by Eliza Houghton
October 10, 2023
in World
0
libcue vulnerability opens security leak in Gnome
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

A vulnerability contained in the libcue library creates a vulnerability in Gnome that allows attackers to inject malicious code into victims with just one click. Updates for Gnome are available that resolve the issue. IT managers should apply them quickly.

Advertisement

As Kevin Backhouse from Github Security Lab writes in an analysis, this is a potential memory scrambling in the libcue library. CUE is more likely to mean something to older people. This is metadata about CD images, such as the start and end times of the individual tracks. According to Backhouse, these are still used in the context of the FLAC audio codec.

Gnome vulnerability: Inconspicuous library with a big impact

That’s why numerous audio players like Audacious still process such files today. Gnome also comes with the tracker-miners application. This indexes the files in the user home directory to make them easily searchable. If files are stored or changed in certain subdirectories of the home directory such as ~/Downloads, tracker-miners updates the index.

An attacker therefore only needs to convince a potential victim to click on a link that leads to downloading the malicious code. This is finally executed through automatic indexing.

Incorrect processing in libcue

libcue contained a bug when processing the “INDEX” element in the cue sheets. The error can be triggered if “INDEX 4294567296 0” appears in the cue sheet instead of “INDEX 01 00:00:00” (format i.e. index, track number, start time). This creates an integer overflow due to the functions used, as the value 2^32 is converted into -400000 by the atoi function. Another function (track_set_index) does not check the index to see whether it is positive. As a result, the code can write at the location outside the intended memory areas.

Backhouse further explains that he still had to bypass Address Space Layout Randomization (ASLR) for a working proof-of-concept. And a seccomp sandbox that tracker-miners relies on to protect against such exploits. Backhouse is holding back the proof-of-concept code for the time being so that as many IT managers and users as possible can update their Gnome desktop.

Kevin Backhouse clearly enjoyed creating the security alert. In the example cue sheets and music files there are constant references to Rick Astley and his 80s hit “Never gonna give you up”. However, the video or song doesn’t play at any point, so it’s probably an unfinished Rickroll. It’s still a catchy tune for those who still know it.

Gnome users should install the update quickly. For the recently discovered glibc vulnerability, stable proof-of-concept exploits appeared just two days after it became known, allowing malicious actors to easily abuse the vulnerability.

(dmk)

To the home page
#libcue #vulnerability #opens #security #leak #Gnome

Tags: GnomeLeaklibcueOpen SourceopensSecuritySecurity updatesVulnerabilitiesvulnerability
Previous Post

Trial begins against former Rwandan officials for genocide

Next Post

The UN reminds Israel that the total siege of Gaza is prohibited

Eliza Houghton

Eliza Houghton

Related Posts

The fashionable energümeno
World

The fashionable energümeno

by Eliza Houghton
December 10, 2023
The problem continues with the hands: the surreal penalty called against Cádiz against Osasuna
World

The problem continues with the hands: the surreal penalty called against Cádiz against Osasuna

by Eliza Houghton
December 10, 2023
Who is Karina Milei, little sister and strategist of the new president of Argentina
World

Who is Karina Milei, little sister and strategist of the new president of Argentina

by Eliza Houghton
December 10, 2023
Hamas: “No hostage will be released unless exchanged for Palestinian prisoners”
World

Hamas: “No hostage will be released unless exchanged for Palestinian prisoners”

by Eliza Houghton
December 10, 2023
A powerless Spain collapses against the Netherlands (29-21) and depends on a carom to go to the women’s handball pre-Olympic
World

A powerless Spain collapses against the Netherlands (29-21) and depends on a carom to go to the women’s handball pre-Olympic

by Eliza Houghton
December 10, 2023
Next Post
The UN reminds Israel that the total siege of Gaza is prohibited

The UN reminds Israel that the total siege of Gaza is prohibited

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Premium Content

How to fight digital aging for the skin

How to fight digital aging for the skin

October 12, 2023
c’t Photography: Photo tours Germany, Austria, Switzerland

c’t Photography: Photo tours Germany, Austria, Switzerland

November 25, 2023
Java 21 is one of the most exciting releases in recent years

Java 21 is one of the most exciting releases in recent years

September 19, 2023

Browse by Category

  • Science
  • Sports
  • World

Browse by Tags

America amnesty Apple Artificial Intelligence attack attacks China Court data due Economy Europe Gaza Gaza Strip Google government Hamas health investiture iOS iPhone Israel Latin America law live Madrid Microsoft million news people Politics PSOE Russia Security Spain Sports Sánchez Ukraine United States Updates Vulnerabilities war workshop world years
Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.

Categories

  • Science
  • Sports
  • World

Browse by Tag

America amnesty Apple Artificial Intelligence attack attacks China Court data due Economy Europe Gaza Gaza Strip Google government Hamas health investiture iOS iPhone Israel Latin America law live Madrid Microsoft million news people Politics PSOE Russia Security Spain Sports Sánchez Ukraine United States Updates Vulnerabilities war workshop world years

Recent Posts

  • The fashionable energümeno
  • The problem continues with the hands: the surreal penalty called against Cádiz against Osasuna
  • Who is Karina Milei, little sister and strategist of the new president of Argentina
  • About Us
  • Home
  • Privacy Policy
  • Terms and Conditions

© Aroged 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© Aroged 2023. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.