Close Menu
Ztoog
    What's Hot
    AI

    UCI and Harvard Researchers Introduce TalkToModel that Explains Machine Learning Models to its Users

    Crypto

    Panel Of Market Experts Predict When Ethereum Price Will Cross $14,000

    Gadgets

    17 Best Wireless Earbuds (2023): Truly Wireless, Cheap, Luxe, and More

    Important Pages:
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    Facebook X (Twitter) Instagram Pinterest
    Facebook X (Twitter) Instagram Pinterest
    Ztoog
    • Home
    • The Future

      Can work-life balance tracking improve well-being?

      Any wall can be turned into a camera to see around corners

      JD Vance and President Trump’s Sons Hype Bitcoin at Las Vegas Conference

      AI may already be shrinking entry-level jobs in tech, new research suggests

      Today’s NYT Strands Hints, Answer and Help for May 26 #449

    • Technology

      Elon Musk tries to stick to spaceships

      A Replit employee details a critical security flaw in web apps created using AI-powered app builder Lovable that exposes API keys and personal info of app users (Reed Albergotti/Semafor)

      Gemini in Google Drive can now help you skip watching that painfully long Zoom meeting

      Apple iPhone exports from China to the US fall 76% as India output surges

      Today’s NYT Wordle Hints, Answer and Help for May 26, #1437

    • Gadgets

      Future-proof your career by mastering AI skills for just $20

      8 Best Vegan Meal Delivery Services and Kits (2025), Tested and Reviewed

      Google Home is getting deeper Gemini integration and a new widget

      Google Announces AI Ultra Subscription Plan With Premium Features

      Google shows off Android XR-based glasses, announces Warby Parker team-up

    • Mobile

      Deals: the Galaxy S25 series comes with a free tablet, Google Pixels heavily discounted

      Microsoft is done being subtle – this new tool screams “upgrade now”

      Wallpaper Wednesday: Android wallpapers 2025-05-28

      Google can make smart glasses accessible with Warby Parker, Gentle Monster deals

      vivo T4 Ultra specs leak

    • Science

      June skygazing: A strawberry moon, the summer solstice… and Asteroid Day!

      Analysts Say Trump Trade Wars Would Harm the Entire US Energy Sector, From Oil to Solar

      Do we have free will? Quantum experiments may soon reveal the answer

      Was Planet Nine exiled from the solar system as a baby?

      How farmers can help rescue water-loving birds

    • AI

      Fueling seamless AI at scale

      Rationale engineering generates a compact new tool for gene therapy | Ztoog

      The AI Hype Index: College students are hooked on ChatGPT

      Learning how to predict rare kinds of failures | Ztoog

      Anthropic’s new hybrid AI model can work on tasks autonomously for hours at a time

    • Crypto

      Bitcoin Maxi Isn’t Buying Hype Around New Crypto Holding Firms

      GameStop bought $500 million of bitcoin

      CoinW Teams Up with Superteam Europe to Conclude Solana Hackathon and Accelerate Web3 Innovation in Europe

      Ethereum Net Flows Turn Negative As Bulls Push For $3,500

      Bitcoin’s Power Compared To Nuclear Reactor By Brazilian Business Leader

    Ztoog
    Home » CD-indexing cue files are the core of a serious Linux remote code exploit
    Gadgets

    CD-indexing cue files are the core of a serious Linux remote code exploit

    Facebook Twitter Pinterest WhatsApp
    CD-indexing cue files are the core of a serious Linux remote code exploit
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp

    Enlarge / Cue files was a lot better-known, again once we all used CD-Rs to make authorized backup copies of materials that we owned outright.

    Getty Images

    It has been a very very long time since the common laptop consumer considered .cue files, or cue sheets, the metadata bits that describe the tracks of an optical disc, like a CD or DVD. But cue sheets are getting consideration once more, for all the mistaken causes. They’re at the coronary heart of a one-click exploit that might give an attacker code execution on Linux methods with GNOME desktops.

    CVE-2023-43641, disclosed by GitHub on October 9, is a reminiscence corruption (or out-of-bounds array writing) subject in the libcue library, which parses cue sheets. NIST has but to supply a rating for the subject, however GitHub’s submission charges it an 8.8, or “High.” While the vulnerability has been patched in the core library, Linux distributions might want to replace their desktops to repair it.

    GNOME desktops have, by default, a “tracker miner” that robotically updates at any time when sure file areas in a consumer’s dwelling listing are modified. If a consumer was compelled to obtain a cue sheet that took benefit of libcue’s vulnerability, GNOME’s indexing tracker would learn the cue sheet, and code in that sheet might be executed.

    • Part one of the .cue-based exploit instance: An Ubuntu desktop, with a browser open, downloading a CUE file.


      Kevin Backhouse / GitHub

    • Part 2: A calculator instantly pops up, with “1337” in the numerical show. You can think about that almost all exploits would have far worse penalties.


      Kevin Backhouse / GitHub

    Kevin Backhouse, a member of GitHub’s Security Lab, gives a video demonstration of the exploit in his weblog submit however has not but revealed the proof of idea to permit for patching. You can take a look at your system’s vulnerability in opposition to a take a look at cue sheet he gives, which ought to set off “a benign crash.”

    Advertisement

    The bug is restricted to how libcue reads the index of a disc observe or its quantity and size. Because of the system instruments it makes use of, you may trick libcue into registering a damaging quantity for an index. Then, as a result of one other half of the scanning routine does not test whether or not an index quantity is damaging earlier than it writes it to an array, an attacker can write exterior the array’s bounds. Backhouse’s proposed repair provides a single situation test to the index-setting routine.

    Backhouse’s weblog submit explains additional how tracker-miners, like these in GNOME, are notably weak to this type of exploit.

    The present resolution is for customers of GNOME-based distributions to replace their methods as quickly as potential. The vulnerability in libcue is patched as of model 2.3.0. Libcue is usually a quite quiet mission, maintained largely by Ilya Lipnitskiy alone. It illustrates, but once more, the huge quantities of technological infrastructure underpinned by tiny, unpaid initiatives.

    This is not Backhouse’s first contribution to broad Linux vulnerabilities. He has beforehand discovered points with commonplace customers changing into root with a few instructions and a Polkit exploit that additionally supplied root entry. Backhouse, regardless of being a recurring bearer of dangerous information, added this footnote to his most up-to-date vulnerability disclosure: “I presently run Ubuntu 23.04 as my most important OS and I love the GNOME desktop setting.”

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp

    Related Posts

    Gadgets

    Future-proof your career by mastering AI skills for just $20

    Gadgets

    8 Best Vegan Meal Delivery Services and Kits (2025), Tested and Reviewed

    Gadgets

    Google Home is getting deeper Gemini integration and a new widget

    Gadgets

    Google Announces AI Ultra Subscription Plan With Premium Features

    Gadgets

    Google shows off Android XR-based glasses, announces Warby Parker team-up

    Gadgets

    The market’s down, but this OpenAI for the stock market can help you trade up

    Gadgets

    We Hand-Picked the 24 Best Deals From the 2025 REI Anniversary Sale

    Gadgets

    “Google wanted that”: Nextcloud decries Android permissions as “gatekeeping”

    Leave A Reply Cancel Reply

    Follow Us
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    Top Posts
    Science

    NASA HQ picked their best photos of the year. Here are our 13 favorites.

    On September 24, 2023, a capsule from NASA’s OSIRIS-REx mission floated again to Earth, touchdown…

    Technology

    Detect Quakes With “Raspberry Shakes”

    I’ve solely as soon as felt an earthquake—in 1985, when a magnitude-4 temblor occurred simply…

    Mobile

    Watch out for this Gmail scam that could easily fool you

    A scam focusing on Gmail account holders has been making the rounds and you could…

    Science

    JWST celebrates first year of science with awesome star-forming image

    The Rho Ophiuchi cloud complicated, captured in infrared by the James Webb Space TelescopeNASA, ESA,…

    Science

    Why symmetry is so fundamental to our understanding of the universe

    Shutterstock/Mariia Tagirova YOU may keep in mind studying about symmetry at college. Maybe a trainer…

    Our Picks
    AI

    “Periodic table of machine learning” could fuel AI discovery | Ztoog

    Gadgets

    OnePlus Nord Buds 2r Review: Refined or Rushed?

    The Future

    Samsung Galaxy Z Flip 5 Hands-On: Bigger Display, More Personal Customizations

    Categories
    • AI (1,494)
    • Crypto (1,754)
    • Gadgets (1,805)
    • Mobile (1,851)
    • Science (1,867)
    • Technology (1,803)
    • The Future (1,649)
    Most Popular
    AI

    Meet MetaGPT: The Open-Source AI Framework That Transforms GPTs into Engineers, Architects, and Managers

    Mobile

    Sharing WhatsApp statuses on Android could soon get smoother

    Gadgets

    The best humidifiers for babies in 2024

    Ztoog
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    © 2025 Ztoog.

    Type above and press Enter to search. Press Esc to cancel.