CVE-2023-47480

NameCVE-2023-47480
DescriptionAn issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3895-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
puredata (PTS)bullseye0.51.4-1vulnerable
bullseye (security)0.51.4-1+deb11u1fixed
bookworm0.53.1+ds-2vulnerable
sid, trixie0.55.1+ds-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
puredatasourcebullseye0.51.4-1+deb11u1DLA-3895-1
puredatasource(unstable)0.54.1+ds-1

Notes

[bookworm] - puredata <no-dsa> (Minor issue)
https://github.com/pure-data/pure-data/issues/2063
https://github.com/pure-data/pure-data/commit/0b5e467b8728b3ed56e1a8ee5b367ce78e7e6e5d (0.54-1test1)

Search for package or bug name: Reporting problems