{"id":"UBUNTU-CVE-2023-43091","details":"A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbitrary code.","modified":"2025-10-24T05:02:16Z","published":"2024-11-17T13:15:00Z","upstream":["CVE-2023-43091"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-43091"},{"type":"REPORT","url":"https://gitlab.gnome.org/GNOME/gnome-maps/-/issues/588"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-43091"}],"affected":[{"package":{"name":"gnome-maps","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/gnome-maps@3.18.4-0ubuntu1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.16.2-1ubuntu1","3.18.1-2","3.18.2-1","3.18.3-0ubuntu1","3.18.4-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"gnome-maps","binary_version":"3.18.4-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-43091.json"}},{"package":{"name":"gnome-maps","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/gnome-maps@3.28.1-1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.26.1-1","3.26.2-1","3.26.2-2","3.26.2-3","3.27.90-1","3.27.92-1","3.28.0-1","3.28.1-1"],"ecosystem_specific":{"binaries":[{"binary_name":"gnome-maps","binary_version":"3.28.1-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-43091.json"}},{"package":{"name":"gnome-maps","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/gnome-maps@3.36.1-1ubuntu1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.34.1-1","3.35.90-1","3.36.0-1","3.36.1-1","3.36.1-1ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_version":"3.36.1-1ubuntu1","binary_name":"gnome-maps"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-43091.json"}},{"package":{"name":"gnome-maps","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/gnome-maps@42.3-0ubuntu1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["40.5-1","41.0-1build1","41.1-1","41.2-1","41.4-1","42.0-1","42.1-0ubuntu1","42.3-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"gnome-maps","binary_version":"42.3-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-43091.json"}},{"package":{"name":"gnome-maps","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/gnome-maps@46.0-1build1?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["45.0-1","45.1-1","45.2-1","45.3-1","45.4-1","46~beta-1","46.0-1","46.0-1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"gnome-maps","binary_version":"46.0-1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-43091.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}