HomeSecurityGNOME Linux: Exposed to RCE attacks via file downloads

GNOME Linux: Exposed to RCE attacks via file downloads

A memory security vulnerability in the open-source libcue could allow attackers to perform RCE attacks on Linux systems running the GNOME desktop environment.

See also: Looney Tunables: Linux bug gives admin access to major distributions

GNOME Linux

libcue, a library designed for parsing cue sheet files, is integrated into the Tracker Miners file metadata indexer , which is included by default in recent versions of GNOME.

CUE files or CUE sheets are simple text files that contain the arrangement of audio tracks on a CD, such as duration, song name, and musician, and are usually accompanied by the FLAC audio file format.

GNOME is a popular desktop environment that is widely used on various Linux distributions such as Debian, Ubuntu, Fedora, Red Hat Enterprise, and SUSE Linux Enterprise.

Attackers can successfully exploit the vulnerability to execute malicious code by taking advantage of the fact that Tracker Miners automatically index all downloaded files to update the search index on GNOME Linux devices.

To exploit this vulnerability , someone would need to download a maliciously crafted .CUE file and then save it to the ~/Downloads folder . The memory vulnerability is caused when Tracker Miners' metadata indexer automatically parses the saved file via the tracker-extract process.

See also: Company announcement about the Free Download Manager site that spread Linux malware

Researcher Kevin Backhouse presented a PoC and shared a video via Twitter earlier. However, the PoC release will be postponed so that all GNOME users can update and protect their systems. While the PoC exploit needs to be adapted to work properly on every Linux distribution, the researcher said that he has already created exploits targeting the Ubuntu 23.04 and Fedora 38 and they work “very reliably.”

RCE

Although successfully exploiting CVE-2023-43641 requires tricking a potential victim into downloading a .cue file, administrators to update systems and address the risks posed by this security vulnerability, as it provides code execution on devices running the latest versions of popular Linux distributions, such as Debian, Fedora, and Ubuntu.

Backhouse has discovered other serious security issues in Linux in recent years, including a privilege escalation vulnerability in the GNOME Display Manager (gdm) and an authentication bypass in the polkit service that is installed by default on many modern Linux platforms

See also: SprySOCKS: New Linux backdoor used in Chinese espionage campaigns

RCE, also known as Remote Code Execution, is a malicious attack tactic in which an attacker executes actions on a computer , guided by a remote location. In practice, the attacker exploits a vulnerability in the victim's software to bypass security. The attacker can then enter commands to execute on the remote computer, with the goal of violating security and accessing personal data. Such an attack can make GNOME Linux systems particularly vulnerable. 

How can a GNOME Linux system be protected from RCE attacks? 

The primary defense against RCE attacks is to regularly update the operating system and all applications running within it. Security updates often contain fixes for known vulnerabilities that attackers can exploit. Additionally, users should use strong and unique passwords for all their accounts, as well as two-factor authentication where possible.

It is worth noting that protecting an operating system from RCE attacks is not just a request that the user must resolve; it is an ongoing process. It requires regular monitoring of the system, updating, and familiarity with the latest attack techniques and defense strategies.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS