Bug 32372 - libcue new security issue CVE-2023-43641
Summary: libcue new security issue CVE-2023-43641
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8TOO MGA8-64-OK MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-10-11 10:16 CEST by Nicolas Salguero
Modified: 2023-10-24 00:07 CEST (History)
6 users (show)

See Also:
Source RPM: libcue-2.2.1-3.mga9.src.rpm
CVE:
Status comment:


Attachments

Description Nicolas Salguero 2023-10-11 10:16:18 CEST
Hi,

CVE-2023-43641 was announced here:
https://www.openwall.com/lists/oss-security/2023/10/09/3

The bug is fixed in version 2.3.0.

Mageia 8 and 9 are also affected.

Best regards,

Nico.
Nicolas Salguero 2023-10-11 10:18:19 CEST

Status comment: (none) => Fixed upstream in 2.3.0
Whiteboard: (none) => MGA9TOO, MGA8TOO
CC: (none) => nicolas.salguero
Source RPM: (none) => libcue-2.2.1-3.mga9.src.rpm

Comment 1 Nicolas Salguero 2023-10-11 13:32:52 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Versions 2.2.1 and prior are vulnerable to out-of-bounds array access. A user of the GNOME desktop environment can be exploited by downloading a cue sheet from a malicious webpage. Because the file is saved to `~/Downloads`, it is then automatically scanned by tracker-miners. And because it has a .cue filename extension, tracker-miners use libcue to parse the file. The file exploits the vulnerability in libcue to gain code execution. (CVE-2023-43641)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-43641
https://www.openwall.com/lists/oss-security/2023/10/09/3
========================

Updated packages in {8|9}/core/updates_testing:
========================
lib(64)cue2-2.3.0-1.mga{8|9}
lib(64)cue-devel-2.3.0-1.mga{8|9}

from SRPM:
libcue-2.3.0-1.mga{8|9}.src.rpm

Status comment: Fixed upstream in 2.3.0 => (none)
Whiteboard: MGA9TOO, MGA8TOO => MGA8TOO
Version: Cauldron => 9
Status: NEW => ASSIGNED
Assignee: bugsquad => qa-bugs

Comment 2 Marja Van Waes 2023-10-11 15:10:01 CEST
Advisory from comment 1 uploaded. Please remove the "advisory" keyword if it needs to be changed

CC: (none) => marja11
Keywords: (none) => advisory

Comment 3 Herman Viaene 2023-10-12 18:09:08 CEST
MGA9-64 Xfce on Acer Aspire 5253
No installation issues
No previous updates, urmpq shows audacious-plugins as dependent
tried a .wav file, error opening stream and Pipewire connection error. Checked MCC - Hardware, shows pulseaudio used. Trae shows a call to libcue.
Tried an avi, same result.
Both the wav and avi play correctly in parole.
Giving up for today.

CC: (none) => herman.viaene

Comment 4 Brian Rockwell 2023-10-19 18:59:35 CEST
MGA8-64, Gnome, Ryzen 2600


The following 2 packages are going to be installed:

- lib64cue-devel-2.3.0-1.mga8.x86_64
- lib64cue2-2.3.0-1.mga8.x86_64

8.6KB of additional disk space will be used.

--

downloaded some cue sheet examples
used music to play music and build playlists.
no issues

Whiteboard: MGA8TOO => MGA8TOO MGA8-64-OK
CC: (none) => brtians1

Comment 5 Brian Rockwell 2023-10-20 02:43:53 CEST
Hi Herman that is an issue with the Audacious build, it defaults to pipewire.  I had no issues once I switched audacious to pulse.

MGA9-64, Gnome

The following 2 packages are going to be installed:

- lib64cue-devel-2.3.0-1.mga9.x86_64
- lib64cue2-2.3.0-1.mga9.x86_64

8.6KB of additional disk space will be used.

-- 

validated sound worked, etc.  no issues

Added audacious

tested that - working as expected after changing from pipewire to pulse

Whiteboard: MGA8TOO MGA8-64-OK => MGA8TOO MGA8-64-OK MGA9-64-OK

Comment 6 Thomas Andrews 2023-10-20 14:12:41 CEST
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Comment 7 Mageia Robot 2023-10-24 00:07:32 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0300.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.