CVE-2023-5557
published 2023-10-13CVE-2023-5557: A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the…
high7.7CVSS 3.1
AVLACHPRNUIRSCCHIHAH
A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tracker-miners | < tracker-miners 3.4.5-1 (trixie) | tracker-miners 3.4.5-1 (trixie) |
| gnome | tracker_miners | < 3.3.2 | 3.3.2 |
| gnome | tracker_miners | >= 3.4.0 < 3.4.5 | 3.4.5 |
| gnome | tracker_miners | >= 3.5.0 < 3.5.3 | 3.5.3 |
| gnome | tracker_miners | >= 3.6.0 < 3.6.1 | 3.6.1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
osv7.7HIGH