CVE-2023-49345
Description
Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or deny access to the application and panel.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Budgie Extras Takeabreak applet stores temporary data in a world-readable location, enabling local attackers to manipulate displayed content or cause denial of service.
Vulnerability
The Budgie Extras Takeabreak applet (part of the budgie-extras package) stores temporary data used between application components in a system location that is accessible to any user with local access to the host. The data file path is easily guessable, allowing an attacker to pre-create the file. This affects versions prior to 1.7.1 [1], [2].
Exploitation
An attacker with local access to the system can pre-create the temporary data file with arbitrary string content or a FIFO (named pipe). If the file is pre-created, the Takeabreak applet will read the attacker-controlled data instead of the intended data, displaying false information to the user. Placing a FIFO can cause the applet to hang or crash, leading to a denial of service. The applet runs in the same thread as the Budgie panel, so crashing the applet can crash the entire panel [2].
Impact
Successful exploitation allows a local attacker to either inject false information (e.g., display an incorrect "next time" message) or cause a denial of service by crashing the Budgie panel. No elevated privileges are required beyond local access [1], [2].
Mitigation
The vulnerability is fixed in budgie-extras version 1.7.1, released on 14 December 2023 [1], [2]. As a workaround, if only one user account exists on the system and physical access to the host is limited, the risk is mitigated. No known exploits in the wild or KEV listing have been reported.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Ubuntu Budgie/Budgie Extrasv5Range: v1.4.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- ubuntu.com/security/notices/USN-6556-1mitrethird-party-advisory
- cve.mitre.org/cgi-bin/cvename.cgimitreissue-tracking
- github.com/UbuntuBudgie/budgie-extras/security/advisories/GHSA-rvhc-rch9-j943mitreissue-tracking
News mentions
0No linked articles in our index yet.