PulseAudio Local Privilege Escalation Vulnerability
BID:27449
Info
PulseAudio Local Privilege Escalation Vulnerability
| Bugtraq ID: | 27449 |
| Class: | Design Error |
| CVE: |
CVE-2008-0008 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 25 2008 12:00AM |
| Updated: | Apr 13 2015 08:21PM |
| Credit: | The issue was reported on SuSe Bugzilla. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Red Hat Fedora 7 PulseAudio PulseAudio 0.9.8 PulseAudio PulseAudio 0.9.6 PulseAudio PulseAudio 0.9.5 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Gentoo Linux |
| Not Vulnerable: |
PulseAudio PulseAudio 0.9.9 |
Discussion
PulseAudio Local Privilege Escalation Vulnerability
PulseAudio is prone to a local privilege-escalation vulnerability because the application fails to properly ensure that it has dropped its privileges.
Exploiting this issue could allow attackers to perform certain actions with superuser privileges.
This vulnerability affects versions prior to PulseAudio 0.9.9.
PulseAudio is prone to a local privilege-escalation vulnerability because the application fails to properly ensure that it has dropped its privileges.
Exploiting this issue could allow attackers to perform certain actions with superuser privileges.
This vulnerability affects versions prior to PulseAudio 0.9.9.
Exploit / POC
PulseAudio Local Privilege Escalation Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
PulseAudio Local Privilege Escalation Vulnerability
Solution:
The vendor has released fixes to address this issue.
NOTE: A seperate additional patch is available for users compiling the application with '-DNDEBUG'.
Please see the references for more information.
Solution:
The vendor has released fixes to address this issue.
NOTE: A seperate additional patch is available for users compiling the application with '-DNDEBUG'.
Please see the references for more information.
References
PulseAudio Local Privilege Escalation Vulnerability
References:
References:
- [pulseaudio-discuss] [ANNOUNCE] PulseAudio 0.9.9 (Lennart Poettering)
- PulseAudio Changeset 2100 (PulseAudio)
- PulseAudio Homepage (PulseAudio)
- Bug 347822 - AUDIT-0: PulseAudio permissions (SuSE)