A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2023:7712 | vendor advisory |
https://access.redhat.com/errata/RHSA-2023:7713 | vendor advisory |
https://access.redhat.com/errata/RHSA-2023:7730 | vendor advisory |
https://access.redhat.com/errata/RHSA-2023:7731 | vendor advisory |
https://access.redhat.com/errata/RHSA-2023:7732 | vendor advisory |
https://access.redhat.com/errata/RHSA-2023:7733 | vendor advisory |
https://access.redhat.com/errata/RHSA-2023:7739 | vendor advisory |
https://access.redhat.com/errata/RHSA-2023:7744 | vendor advisory |
https://access.redhat.com/security/cve/CVE-2023-5557 | third party advisory vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2243096 | third party advisory issue tracking exploit |