Executive Summary
Summary | |
---|---|
Title | PulseAudio vulnerability |
Informations | |||
---|---|---|---|
Name | USN-573-1 | First vendor Publication | 2008-01-31 |
Vendor | Ubuntu | Last vendor Modification | 2008-01-31 |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 7.2 | Attack Range | Local |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
A security issue affects the following Ubuntu releases: Ubuntu 7.04 Ubuntu 7.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 7.04: Ubuntu 7.10: In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: It was discovered that PulseAudio did not properly drop privileges when running as a daemon. Local users may be able to exploit this and gain privileges. The default Ubuntu configuration is not affected. |
Original Source
Url : http://www.ubuntu.com/usn/USN-573-1 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-20 | Improper Input Validation |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:17781 | |||
Oval ID: | oval:org.mitre.oval:def:17781 | ||
Title: | USN-573-1 -- pulseaudio vulnerability | ||
Description: | It was discovered that PulseAudio did not properly drop privileges when running as a daemon. | ||
Family: | unix | Class: | patch |
Reference(s): | USN-573-1 CVE-2008-0008 | Version: | 7 |
Platform(s): | Ubuntu 7.04 Ubuntu 7.10 | Product(s): | pulseaudio |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:20369 | |||
Oval ID: | oval:org.mitre.oval:def:20369 | ||
Title: | DSA-1476-1 pulseaudio - programming error | ||
Description: | Marcus Meissner discovered that the PulseAudio sound server performed insufficient checks when dropping privileges, which could lead to local privilege escalation. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1476-1 CVE-2008-0008 | Version: | 5 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | pulseaudio |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 2 |
OpenVAS Exploits
Date | Description |
---|---|
2009-04-09 | Name : Mandriva Update for pulseaudio MDVSA-2008:027 (pulseaudio) File : nvt/gb_mandriva_MDVSA_2008_027.nasl |
2009-03-23 | Name : Ubuntu Update for pulseaudio vulnerability USN-573-1 File : nvt/gb_ubuntu_USN_573_1.nasl |
2009-02-17 | Name : Fedora Update for pulseaudio FEDORA-2008-0963 File : nvt/gb_fedora_2008_0963_pulseaudio_fc8.nasl |
2009-02-17 | Name : Fedora Update for pulseaudio FEDORA-2008-0994 File : nvt/gb_fedora_2008_0994_pulseaudio_fc7.nasl |
2008-09-24 | Name : Gentoo Security Advisory GLSA 200802-07 (pulseaudio) File : nvt/glsa_200802_07.nasl |
2008-01-31 | Name : Debian Security Advisory DSA 1476-1 (pulseaudio) File : nvt/deb_1476_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
42842 | PulseAudio pa_drop_root Function Local Privilege Escalation |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2009-04-23 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2008-027.nasl - Type : ACT_GATHER_INFO |
2008-02-14 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200802-07.nasl - Type : ACT_GATHER_INFO |
2008-02-01 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-573-1.nasl - Type : ACT_GATHER_INFO |
2008-01-29 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1476.nasl - Type : ACT_GATHER_INFO |
2008-01-27 | Name : The remote Fedora host is missing a security update. File : fedora_2008-0963.nasl - Type : ACT_GATHER_INFO |
2008-01-27 | Name : The remote Fedora host is missing a security update. File : fedora_2008-0994.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 12:04:55 |
|