Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-0008

Опубликовано: 29 янв. 2008
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 7.2

Описание

The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail via attacks such as resource exhaustion.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

0.9.9-1ubuntu1
edgy

DNE

feisty

released

0.9.5-5ubuntu4.2
gutsy

released

0.9.6-1ubuntu2.1
upstream

released

0.9.9

Показывать по

EPSS

Процентиль: 15%
0.0005
Низкий

7.2 High

CVSS2

Связанные уязвимости

nvd
почти 18 лет назад

The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail via attacks such as resource exhaustion.

debian
почти 18 лет назад

The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 bui ...

github
больше 3 лет назад

The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail via attacks such as resource exhaustion.

EPSS

Процентиль: 15%
0.0005
Низкий

7.2 High

CVSS2