Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.64476
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1838-1)
Summary:The remote host is missing an update for the Debian 'pulseaudio' package(s) announced via the DSA-1838-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'pulseaudio' package(s) announced via the DSA-1838-1 advisory.

Vulnerability Insight:
Tavis Ormandy and Julien Tinnes discovered that the pulseaudio daemon does not drop privileges before re-executing itself, enabling local attackers to increase their privileges.

The old stable distribution (etch) is not affected by this issue.

For the stable distribution (lenny), this problem has been fixed in version 0.9.10-3+lenny1.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you upgrade your pulseaudio packages.

Affected Software/OS:
'pulseaudio' package(s) on Debian 5.

Solution:
Please install the updated package(s).

CVSS Score:
7.2

CVSS Vector:
AV:L/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-1894
20090717 PulseAudio local race condition privilege escalation vulnerability
http://www.securityfocus.com/archive/1/505052/100/0/threaded
35721
http://www.securityfocus.com/bid/35721
35868
http://secunia.com/advisories/35868
35886
http://secunia.com/advisories/35886
35896
http://secunia.com/advisories/35896
DSA-1838
http://www.debian.org/security/2009/dsa-1838
GLSA-200907-13
http://security.gentoo.org/glsa/glsa-200907-13.xml
MDVSA-2009:152
http://www.mandriva.com/security/advisories?name=MDVSA-2009:152
MDVSA-2009:171
http://www.mandriva.com/security/advisories?name=MDVSA-2009:171
USN-804-1
http://www.ubuntu.com/usn/usn-804-1
http://blog.cr0.org/2009/07/old-school-local-root-vulnerability-in.html
http://taviso.decsystem.org/research.html
http://www.akitasecurity.nl/advisory.php?id=AK20090602
https://admin.fedoraproject.org/updates/pulseaudio-0.9.10-1.el5.2
https://bugzilla.redhat.com/show_bug.cgi?id=510071
pulseaudio-suid-privilege-escalation(51804)
https://exchange.xforce.ibmcloud.com/vulnerabilities/51804
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.