An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.
[
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"195968191740061317144171536479167778362",
"338891705644018116632299431110062808512",
"77918548636497656554516166748199715723",
"216734719142769474339022785216113579052"
]
},
"target": {
"file": "src/s_main.c"
},
"source": "https://github.com/pure-data/pure-data/commit/0b5e467b8728b3ed56e1a8ee5b367ce78e7e6e5d",
"id": "CVE-2023-47480-6a655462",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "131346506361158776265261260239492365678",
"length": 1939.0
},
"target": {
"file": "src/s_main.c",
"function": "sys_main"
},
"source": "https://github.com/pure-data/pure-data/commit/0b5e467b8728b3ed56e1a8ee5b367ce78e7e6e5d",
"id": "CVE-2023-47480-e256a880",
"deprecated": false,
"signature_version": "v1"
}
]