cbcvebase.
CVE-2023-5557
published 2023-10-13

CVE-2023-5557: A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the…

high7.7CVSS 3.1
AVLACHPRNUIRSCCHIHAH
A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.

Affected

7 ranges
VendorProductVersion rangeFixed in
debiantracker-miners< tracker-miners 3.4.5-1 (trixie)tracker-miners 3.4.5-1 (trixie)
gnometracker_miners< 3.3.23.3.2
gnometracker_miners>= 3.4.0 < 3.4.53.4.5
gnometracker_miners>= 3.5.0 < 3.5.33.5.3
gnometracker_miners>= 3.6.0 < 3.6.13.6.1
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.17.7HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
osv7.7HIGH