7.2
CVE-2008-0008
- EPSS 0.56%
- Veröffentlicht 29.01.2008 00:00:00
- Zuletzt bearbeitet 16.06.2026 22:48:45
- Erkennungen
The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail via attacks such as resource exhaustion.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pulseaudio ≫ Pulseaudio Version 0.9.6
Mandrakesoft ≫ Mandrake Linux Version 2007.1
Mandrakesoft ≫ Mandrake Linux Version 2007.1 Edition x86_64
Mandrakesoft ≫ Mandrake Linux Version 2008.0
Mandrakesoft ≫ Mandrake Linux Version 2008.0 Edition x86_64
Redhat ≫ Fedora Version 7
Redhat ≫ Fedora Version 8
Mandrakesoft ≫ Mandrake Linux Version 2007.1 Edition x86_64
Mandrakesoft ≫ Mandrake Linux Version 2008.0
Mandrakesoft ≫ Mandrake Linux Version 2008.0 Edition x86_64
Redhat ≫ Fedora Version 7
Redhat ≫ Fedora Version 8
Pulseaudio ≫ Pulseaudio Version 0.9.8
Mandrakesoft ≫ Mandrake Linux Version 2007.1
Mandrakesoft ≫ Mandrake Linux Version 2007.1 Edition x86_64
Mandrakesoft ≫ Mandrake Linux Version 2008.0
Mandrakesoft ≫ Mandrake Linux Version 2008.0 Edition x86_64
Redhat ≫ Fedora Version 7
Redhat ≫ Fedora Version 8
Mandrakesoft ≫ Mandrake Linux Version 2007.1 Edition x86_64
Mandrakesoft ≫ Mandrake Linux Version 2008.0
Mandrakesoft ≫ Mandrake Linux Version 2008.0 Edition x86_64
Redhat ≫ Fedora Version 7
Redhat ≫ Fedora Version 8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.56% | 0.419 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://bugs.gentoo.org/show_bug.cgi?id=207214
http://pulseaudio.org/changeset/2100
http://secunia.com/advisories/28608
http://secunia.com/advisories/28623
http://secunia.com/advisories/28738
http://secunia.com/advisories/28952
http://security.gentoo.org/glsa/glsa-200802-07.xml
http://www.debian.org/security/2008/dsa-1476
http://www.mandriva.com/security/advisories?name=MDVSA-2008:027
http://www.securityfocus.com/bid/27449
http://www.ubuntu.com/usn/usn-573-1
http://www.vupen.com/english/advisories/2008/0283
https://bugzilla.novell.com/show_bug.cgi?id=347822
https://bugzilla.redhat.com/show_bug.cgi?id=425481
https://exchange.xforce.ibmcloud.com/vulnerabilities/39992
https://tango.0pointer.de/pipermail/pulseaudio-discuss/2008-January/001228.html
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00852.html
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00869.html