Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-16123

Опубликовано: 04 дек. 2020
Источник: ubuntu
Приоритет: medium
CVSS2: 2.1
CVSS3: 4.4

Описание

An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a client connection from a snap as coming from a snap if SCM_CREDENTIALS were missing, allowing the snap to connect to PulseAudio without proper confinement. This could be exploited by an attacker to expose sensitive information. Fixed in 1:13.99.3-1ubuntu2, 1:13.99.2-1ubuntu2.1, 1:13.99.1-1ubuntu3.8, 1:11.1-1ubuntu7.11, and 1:8.0-0ubuntu3.15.

РелизСтатусПримечание
bionic

released

1:11.1-1ubuntu7.11
devel

released

1:13.99.3-1ubuntu2
esm-infra-legacy/trusty

DNE

esm-infra/bionic

released

1:11.1-1ubuntu7.11
esm-infra/focal

released

1:13.99.1-1ubuntu3.8
esm-infra/xenial

released

1:8.0-0ubuntu3.15
focal

released

1:13.99.1-1ubuntu3.8
groovy

released

1:13.99.2-1ubuntu2.1
precise/esm

DNE

trusty

ignored

end of standard support

Показывать по

2.1 Low

CVSS2

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
redhat
около 5 лет назад

An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a client connection from a snap as coming from a snap if SCM_CREDENTIALS were missing, allowing the snap to connect to PulseAudio without proper confinement. This could be exploited by an attacker to expose sensitive information. Fixed in 1:13.99.3-1ubuntu2, 1:13.99.2-1ubuntu2.1, 1:13.99.1-1ubuntu3.8, 1:11.1-1ubuntu7.11, and 1:8.0-0ubuntu3.15.

CVSS3: 4.4
nvd
около 5 лет назад

An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a client connection from a snap as coming from a snap if SCM_CREDENTIALS were missing, allowing the snap to connect to PulseAudio without proper confinement. This could be exploited by an attacker to expose sensitive information. Fixed in 1:13.99.3-1ubuntu2, 1:13.99.2-1ubuntu2.1, 1:13.99.1-1ubuntu3.8, 1:11.1-1ubuntu7.11, and 1:8.0-0ubuntu3.15.

CVSS3: 4.4
debian
около 5 лет назад

An Ubuntu-specific patch in PulseAudio created a race condition where ...

github
больше 3 лет назад

An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a client connection from a snap as coming from a snap if SCM_CREDENTIALS were missing, allowing the snap to connect to PulseAudio without proper confinement. This could be exploited by an attacker to expose sensitive information. Fixed in 1:13.99.3-1ubuntu2, 1:13.99.2-1ubuntu2.1, 1:13.99.1-1ubuntu3.8, 1:11.1-1ubuntu7.11, and 1:8.0-0ubuntu3.15.

2.1 Low

CVSS2

4.4 Medium

CVSS3