CVE-2008-0008
Published Jan 29, 2008
Last updated 10 months ago
Overview
- Description
- The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail via attacks such as resource exhaustion.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-20
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:mandrakesoft:mandrake_linux:2007.1:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "19D64247-F0A0-4984-84EA-B63FC901F002" }, { "criteria": "cpe:2.3:o:mandrakesoft:mandrake_linux:2007.1:*:x86_64:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "316AA6EB-7191-479E-99D5-40DA79E340E7" }, { "criteria": "cpe:2.3:o:mandrakesoft:mandrake_linux:2008.0:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CB7AD2F3-451D-4F37-A6F3-DE676804BBA3" }, { "criteria": "cpe:2.3:o:mandrakesoft:mandrake_linux:2008.0:*:x86_64:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5FE8C9E7-15C3-4F89-8E54-C9691FAD4E4C" }, { "criteria": "cpe:2.3:o:redhat:fedora:7:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "EE2027FA-357A-4BE3-9043-6DE8307C040A" }, { "criteria": "cpe:2.3:o:redhat:fedora:8:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C8E8256F-3FB6-45B2-8F03-02A61C10FAF0" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:pulseaudio:pulseaudio:0.9.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F7E8B62F-B9DE-4209-9531-8FA6C4869295" }, { "criteria": "cpe:2.3:a:pulseaudio:pulseaudio:0.9.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "21A099DF-9D09-4698-96FC-00D188FD9E36" } ], "operator": "OR" } ], "operator": "AND" } ]