this post was submitted on 09 Oct 2023
48 points (100.0% liked)

Arch Linux

7173 readers
11 users here now

The beloved lightweight distro

founded 4 years ago
MODERATORS
48
Gnome 45 is here (archlinux.org)
submitted 1 year ago* (last edited 1 year ago) by infeeeee@lemm.ee to c/archlinux@lemmy.ml
 

Can you count your broken extensions?

Official guide for extension maintainers: https://gjs.guide/extensions/upgrading/gnome-shell-45.html

you are viewing a single comment's thread
view the rest of the comments
[–] redw0rm@kerala.party 4 points 1 year ago* (last edited 1 year ago)

Since that post was'nt available for me atm, just reposting relevant Github blog : 1-Click RCE on GNOME

The TL;DR

libcue is a library used for parsing cue sheets—a metadata format for describing the layout of the tracks on a CD. it’s used by tracker-miners: an application that’s included with GNOME.The index is automatically updated when you add or modify a file in certain subdirectories of your home directory, in particular including ~/Downloads. To make a long story short, that means that inadvertently clicking a malicious link is all it takes for an attacker to exploit CVE-2023-43641 and get code execution on your computer.