VYPR
Unrated severityNVD Advisory· Published Dec 14, 2023· Updated May 21, 2025

CVE-2023-49345

CVE-2023-49345

Description

Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or deny access to the application and panel.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Budgie Extras Takeabreak applet stores temporary data in a world-readable location, enabling local attackers to manipulate displayed content or cause denial of service.

Vulnerability

The Budgie Extras Takeabreak applet (part of the budgie-extras package) stores temporary data used between application components in a system location that is accessible to any user with local access to the host. The data file path is easily guessable, allowing an attacker to pre-create the file. This affects versions prior to 1.7.1 [1], [2].

Exploitation

An attacker with local access to the system can pre-create the temporary data file with arbitrary string content or a FIFO (named pipe). If the file is pre-created, the Takeabreak applet will read the attacker-controlled data instead of the intended data, displaying false information to the user. Placing a FIFO can cause the applet to hang or crash, leading to a denial of service. The applet runs in the same thread as the Budgie panel, so crashing the applet can crash the entire panel [2].

Impact

Successful exploitation allows a local attacker to either inject false information (e.g., display an incorrect "next time" message) or cause a denial of service by crashing the Budgie panel. No elevated privileges are required beyond local access [1], [2].

Mitigation

The vulnerability is fixed in budgie-extras version 1.7.1, released on 14 December 2023 [1], [2]. As a workaround, if only one user account exists on the system and physical access to the host is limited, the risk is mitigated. No known exploits in the wild or KEV listing have been reported.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.