A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-tracker-miners | Dec 13, 2023 | Oct 13, 2023 | |
| Centos_linux | — | centos-upgrade-tracker-minerscentos-upgrade-tracker-miners-debuginfocentos-upgrade-tracker-miners-debugsource | Dec 12, 2023 | Oct 13, 2023 |
| Debian | no-fix-debian-deb-package | May 15, 2025 | Oct 13, 2023 | |
| Gentoo Linux | gentoo-linux-upgrade-app-misc-tracker-miners | May 15, 2025 | Oct 13, 2023 | |
| Oracle_linux | — | oracle-linux-upgrade-tracker-miners | Dec 12, 2023 | Sep 26, 2023 |
| Redhat_linux | redhat-upgrade-tracker-minersredhat-upgrade-tracker-miners-debuginforedhat-upgrade-tracker-miners-debugsource | Dec 12, 2023 | Oct 13, 2023 | |
| Rocky_linux | rocky-upgrade-tracker-minersrocky-upgrade-tracker-miners-debuginforocky-upgrade-tracker-miners-debugsource | Aug 28, 2024 | Oct 13, 2023 | |
| Suse | — | suse-upgrade-tracker-miner-filessuse-upgrade-tracker-minerssuse-upgrade-tracker-miners-lang | Dec 19, 2023 | Oct 13, 2023 |
| Ubuntu | ubuntu-upgrade-tracker-extract | Nov 23, 2023 | Oct 13, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub