CVE-2023-47480

unknown
Published — · Modified —
CVSS v3
—
CVSS v4 NEW
—
not yet in upstream
VIR risk
—

Description

An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.

Predictions

Exploit likelihood
20%
Patch ETA
—

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2023-47480 NameCVE-2023-47480 DescriptionAn issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) ReferencesDLA-3895-1 Vulnerable and fixed packages The table below…

CVE-2023-47480

NameCVE-2023-47480
DescriptionAn issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3895-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
puredata (PTS)bullseye0.51.4-1vulnerable
bullseye (security)0.51.4-1+deb11u1fixed
bookworm0.53.1+ds-2+deb12u1fixed
trixie0.55.2+ds-2fixed
forky0.56.2+ds-1fixed
sid0.56.3+ds-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
puredatasourcebullseye0.51.4-1+deb11u1DLA-3895-1
puredatasourcebookworm0.53.1+ds-2+deb12u1
puredatasource(unstable)0.54.1+ds-1

Notes

https://github.com/pure-data/pure-data/issues/2063
https://github.com/pure-data/pure-data/commit/0b5e467b8728b3ed56e1a8ee5b367ce78e7e6e5d (0.54-1test1)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://github.com/pure-data/pure-data/issues/2063https://github.com/pure-data/pure-data/commit/0b5e467b8728b3ed56e1a8ee5b367ce78e7e6e5d (0.54-1test1)

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0.53.1+ds-2+deb12u1
debian debianbullseyefixed0.51.4-1+deb11u1
debian debianforkyfixed0.54.1+ds-1
debian debiansidfixed0.54.1+ds-1
debian debiantrixiefixed0.54.1+ds-1

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.