Description
libcue provides an API for parsing and extracting data from CUE sheets. Versions 2.2.1 and prior are vulnerable to out-of-bounds array access. A user of the GNOME desktop environment can be exploited by downloading a cue sheet from a malicious webpage. Because the file is saved to `~/Downloads`, it is then automatically scanned by tracker-miners. And because it has a .cue filename extension, tracker-miners use libcue to parse the file. The file exploits the vulnerability in libcue to gain code execution. This issue is patched in version 2.3.0.
Published: 2023-10-09
Score: 8.8 High
EPSS: 80.2% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-3615-1 libcue security update
Debian DSA Debian DSA DSA-5524-1 libcue security update
Ubuntu USN Ubuntu USN USN-6423-1 CUE vulnerability
Ubuntu USN Ubuntu USN USN-6423-2 CUE vulnerability
History

Wed, 17 Dec 2025 05:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'No', 'Exploitation': 'PoC', 'Technical Impact': 'Total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 14 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:lipnitsk:libcue:-:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'No', 'Exploitation': 'PoC', 'Technical Impact': 'Total'}, 'version': '2.0.3'}


Subscriptions

Debian Debian Linux
Fedoraproject Fedora
Lipnitsk Libcue
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-16T18:23:25.393Z

Reserved: 2023-09-20T15:35:38.146Z

Link: CVE-2023-43641

cve-icon Vulnrichment

Updated: 2024-08-02T19:44:43.840Z

cve-icon NVD

Status : Modified

Published: 2023-10-09T22:15:12.707

Modified: 2024-11-21T08:24:31.480

Link: CVE-2023-43641

cve-icon Redhat

Severity : Important

Publid Date: 2023-10-09T00:00:00Z

Links: CVE-2023-43641 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses