▲ 47 ▼ Gnome 45 is here (archlinux.org) submitted 2 years ago* (last edited 2 years ago) by infeeeee@lemm.ee to c/archlinux@lemmy.ml 26 comments fedilink hide all child comments Can you count your broken extensions? Official guide for extension maintainers: https://gjs.guide/extensions/upgrading/gnome-shell-45.html
[–] reddit_sux@lemmy.world 6 points 2 years ago (1 child) Gnome users beware and upgrade libcue. https://lemmy.ndlug.org/post/270908 permalink fedilink source hideshow 2 child comments replies: [–] redw0rm@kerala.party 4 points 2 years ago* Since that post was'nt available for me atm, just reposting relevant Github blog : 1-Click RCE on GNOME The TL;DR libcue is a library used for parsing cue sheets—a metadata format for describing the layout of the tracks on a CD. it’s used by tracker-miners: an application that’s included with GNOME.The index is automatically updated when you add or modify a file in certain subdirectories of your home directory, in particular including ~/Downloads. To make a long story short, that means that inadvertently clicking a malicious link is all it takes for an attacker to exploit CVE-2023-43641 and get code execution on your computer. permalink fedilink source parent
[–] redw0rm@kerala.party 4 points 2 years ago* Since that post was'nt available for me atm, just reposting relevant Github blog : 1-Click RCE on GNOME The TL;DR libcue is a library used for parsing cue sheets—a metadata format for describing the layout of the tracks on a CD. it’s used by tracker-miners: an application that’s included with GNOME.The index is automatically updated when you add or modify a file in certain subdirectories of your home directory, in particular including ~/Downloads. To make a long story short, that means that inadvertently clicking a malicious link is all it takes for an attacker to exploit CVE-2023-43641 and get code execution on your computer. permalink fedilink source parent