A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "tracker-extract", "binary_version": "3.3.3-0ubuntu0.20.04.1" }, { "binary_name": "tracker-extract-dbgsym", "binary_version": "3.3.3-0ubuntu0.20.04.1" }, { "binary_name": "tracker-miner-fs", "binary_version": "3.3.3-0ubuntu0.20.04.1" }, { "binary_name": "tracker-miner-fs-dbgsym", "binary_version": "3.3.3-0ubuntu0.20.04.1" } ] }