Close Menu
Ztoog
    What's Hot
    Science

    The experiments that could finally explain gravity

    Technology

    SmileDirectClub Shut Down: What We Know About Payments and Finding New Treatment

    Technology

    Wattpad is revamping its creator program and making it more accessible

    Important Pages:
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    Facebook X (Twitter) Instagram Pinterest
    Facebook X (Twitter) Instagram Pinterest
    Ztoog
    • Home
    • The Future

      What is Project Management? 5 Best Tools that You Can Try

      Operational excellence strategy and continuous improvement

      Hannah Fry: AI isn’t as powerful as we think

      FanDuel goes all in on responsible gaming push with new Play with a Plan campaign

      Gettyimages.com Is the Best Website on the Internet Right Now

    • Technology

      Iran war: How could it end?

      Democratic senators question CFTC staffing cuts in Chicago enforcement office

      Google’s Cloud AI lead on the three frontiers of model capability

      AMD agrees to backstop a $300M loan from Goldman Sachs for Crusoe to buy AMD AI chips, the first known case of AMD chips used as debt collateral (The Information)

      Productivity apps failed me when I needed them most

    • Gadgets

      macOS Tahoe 26.3.1 update will “upgrade” your M5’s CPU to new “super” cores

      Lenovo Shows Off a ThinkBook Modular AI PC Concept With Swappable Ports and Detachable Displays at MWC 2026

      POCO M8 Review: The Ultimate Budget Smartphone With Some Cons

      The Mission: Impossible of SSDs has arrived with a fingerprint lock

      6 Best Phones With Headphone Jacks (2026), Tested and Reviewed

    • Mobile

      Android’s March update is all about finding people, apps, and your missing bags

      Watch Xiaomi’s global launch event live here

      Our poll shows what buyers actually care about in new smartphones (Hint: it’s not AI)

      Is Strava down for you? You’re not alone

      The Motorola Razr FIFA World Cup 2026 Edition was literally just unveiled, and Verizon is already giving them away

    • Science

      Big Tech Signs White House Data Center Pledge With Good Optics and Little Substance

      Inside the best dark matter detector ever built

      NASA’s Artemis moon exploration programme is getting a major makeover

      Scientists crack the case of “screeching” Scotch tape

      Blue-faced, puffy-lipped monkey scores a rare conservation win

    • AI

      Online harassment is entering its AI era

      Meet NullClaw: The 678 KB Zig AI Agent Framework Running on 1 MB RAM and Booting in Two Milliseconds

      New method could increase LLM training efficiency | Ztoog

      The human work behind humanoid robots is being hidden

      NVIDIA Releases DreamDojo: An Open-Source Robot World Model Trained on 44,711 Hours of Real-World Human Video Data

    • Crypto

      Google paid startup Form Energy $1B for its massive 100-hour battery

      Ethereum Breakout Alert: Corrective Channel Flip Sparks Impulsive Wave

      Show Your ID Or No Deal

      Jane Street sued for alleged front-running trades that accelerated Terraform Labs meltdown

      Bitcoin Trades Below ETF Cost-Basis As MVRV Signals Mounting Pressure

    Ztoog
    Home » CD-indexing cue files are the core of a serious Linux remote code exploit
    Gadgets

    CD-indexing cue files are the core of a serious Linux remote code exploit

    Facebook Twitter Pinterest WhatsApp
    CD-indexing cue files are the core of a serious Linux remote code exploit
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp

    Enlarge / Cue files was a lot better-known, again once we all used CD-Rs to make authorized backup copies of materials that we owned outright.

    Getty Images

    It has been a very very long time since the common laptop consumer considered .cue files, or cue sheets, the metadata bits that describe the tracks of an optical disc, like a CD or DVD. But cue sheets are getting consideration once more, for all the mistaken causes. They’re at the coronary heart of a one-click exploit that might give an attacker code execution on Linux methods with GNOME desktops.

    CVE-2023-43641, disclosed by GitHub on October 9, is a reminiscence corruption (or out-of-bounds array writing) subject in the libcue library, which parses cue sheets. NIST has but to supply a rating for the subject, however GitHub’s submission charges it an 8.8, or “High.” While the vulnerability has been patched in the core library, Linux distributions might want to replace their desktops to repair it.

    GNOME desktops have, by default, a “tracker miner” that robotically updates at any time when sure file areas in a consumer’s dwelling listing are modified. If a consumer was compelled to obtain a cue sheet that took benefit of libcue’s vulnerability, GNOME’s indexing tracker would learn the cue sheet, and code in that sheet might be executed.

    • Part one of the .cue-based exploit instance: An Ubuntu desktop, with a browser open, downloading a CUE file.


      Kevin Backhouse / GitHub

    • Part 2: A calculator instantly pops up, with “1337” in the numerical show. You can think about that almost all exploits would have far worse penalties.


      Kevin Backhouse / GitHub

    Kevin Backhouse, a member of GitHub’s Security Lab, gives a video demonstration of the exploit in his weblog submit however has not but revealed the proof of idea to permit for patching. You can take a look at your system’s vulnerability in opposition to a take a look at cue sheet he gives, which ought to set off “a benign crash.”

    Advertisement

    The bug is restricted to how libcue reads the index of a disc observe or its quantity and size. Because of the system instruments it makes use of, you may trick libcue into registering a damaging quantity for an index. Then, as a result of one other half of the scanning routine does not test whether or not an index quantity is damaging earlier than it writes it to an array, an attacker can write exterior the array’s bounds. Backhouse’s proposed repair provides a single situation test to the index-setting routine.

    Backhouse’s weblog submit explains additional how tracker-miners, like these in GNOME, are notably weak to this type of exploit.

    The present resolution is for customers of GNOME-based distributions to replace their methods as quickly as potential. The vulnerability in libcue is patched as of model 2.3.0. Libcue is usually a quite quiet mission, maintained largely by Ilya Lipnitskiy alone. It illustrates, but once more, the huge quantities of technological infrastructure underpinned by tiny, unpaid initiatives.

    This is not Backhouse’s first contribution to broad Linux vulnerabilities. He has beforehand discovered points with commonplace customers changing into root with a few instructions and a Polkit exploit that additionally supplied root entry. Backhouse, regardless of being a recurring bearer of dangerous information, added this footnote to his most up-to-date vulnerability disclosure: “I presently run Ubuntu 23.04 as my most important OS and I love the GNOME desktop setting.”

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp

    Related Posts

    Gadgets

    macOS Tahoe 26.3.1 update will “upgrade” your M5’s CPU to new “super” cores

    Gadgets

    Lenovo Shows Off a ThinkBook Modular AI PC Concept With Swappable Ports and Detachable Displays at MWC 2026

    Gadgets

    POCO M8 Review: The Ultimate Budget Smartphone With Some Cons

    Gadgets

    The Mission: Impossible of SSDs has arrived with a fingerprint lock

    Gadgets

    6 Best Phones With Headphone Jacks (2026), Tested and Reviewed

    Gadgets

    5 changes to know about in Apple’s latest iOS, macOS, and iPadOS betas

    Gadgets

    Lenovo Unveils AI-Enhanced Legion Y700 (2026): A New Benchmark For Compact Gaming Tablets

    Gadgets

    ASUS Vivobook S16 OLED Review: The Most Practical 16-inch Laptop Right Now

    Leave A Reply Cancel Reply

    Follow Us
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    Top Posts
    Mobile

    Samsung Galaxy Buds3 Pro case battery capacity revealed

    Samsung’s subsequent Galaxy Unpacked occasion is predicted in early to mid-July with Paris because the…

    AI

    Top AI Tools for Data Analysts 2023

    As an interactive analytics and information visualization platform, Tableau can be utilized by somebody unfamiliar…

    Mobile

    Realme Narzo 70 Pro’s announcement set for March 19

    Realme Narzo 70 Pro will arrive on March 19, the corporate confirmed at this time.…

    AI

    CMU Researchers Introduce Unlimiformer: An AI Method for Augmenting Pretrained Encoder-Decoders with an External Datastore to Allow for Unlimited Length Input

    Transformer-based fashions have dominated the pure language processing (NLP) discipline since their introduction in 2017.…

    Science

    Roger Penrose interview: “Consciousness must be beyond computable physics.”

    EARLY in his profession, the University of Oxford mathematician Roger Penrose impressed the artist M.…

    Our Picks
    Mobile

    Judge fails to dismiss suit accusing Apple and Amazon of conspiring to keep iPhone, iPad prices high

    Mobile

    Weekly poll: are macro-enabled ultra wide cameras useful or useless?

    Science

    Weird white dwarf star has a metal scar after eating a planet

    Categories
    • AI (1,560)
    • Crypto (1,826)
    • Gadgets (1,870)
    • Mobile (1,910)
    • Science (1,939)
    • Technology (1,862)
    • The Future (1,716)
    Most Popular
    Technology

    How to Build a Power Grid on the Moon

    Crypto

    Liquid Staking’s $20 Billion Rise Amid Market Uncertainty

    Mobile

    Threads users can finally delete their profile separately from Instagram

    Ztoog
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    © 2026 Ztoog.

    Type above and press Enter to search. Press Esc to cancel.