CVE-2009-0035

alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/alsa-info.sh scripts.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
Affected Products (NVD)
VendorProductVersion
alsa-projectalsa
1.0.19 ≤
𝑥
< 1.0.20
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
alsa-driver
hardy
ignored
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
alsa
suse enterprise desktop 15
1.1.5-4.22
fixed
suse enterprise desktop 15 SP1
1.1.5-6.6.1
fixed
suse enterprise desktop 15 SP2
1.1.5-6.6.1
fixed
suse enterprise sap 12 SP5
1.0.27.2-15.1
fixed
suse enterprise sap 15
1.1.5-4.22
fixed
suse enterprise sap 15 SP1
1.1.5-6.6.1
fixed
suse enterprise sap 15 SP2
1.1.5-6.6.1
fixed
suse enterprise server 12
1.0.27.2-11.4
fixed
suse enterprise server 12 SP2
1.0.27.2-11.4
fixed
suse enterprise server 12 SP3
1.0.27.2-15.1
fixed
suse enterprise server 12 SP4
1.0.27.2-15.1
fixed
suse enterprise server 12 SP5
1.0.27.2-15.1
fixed
suse enterprise server 15
1.1.5-4.22
fixed
suse enterprise server 15 SP1
1.1.5-6.6.1
fixed
suse enterprise server 15 SP2
1.1.5-6.6.1
fixed
alsa-devel
suse enterprise desktop 15
1.1.5-4.22
fixed
suse enterprise desktop 15 SP1
1.1.5-6.6.1
fixed
suse enterprise desktop 15 SP2
1.1.5-6.6.1
fixed
suse enterprise sap 15
1.1.5-4.22
fixed
suse enterprise sap 15 SP1
1.1.5-6.6.1
fixed
suse enterprise sap 15 SP2
1.1.5-6.6.1
fixed
suse enterprise server 15
1.1.5-4.22
fixed
suse enterprise server 15 SP1
1.1.5-6.6.1
fixed
suse enterprise server 15 SP2
1.1.5-6.6.1
fixed
alsa-docs
suse enterprise sap 12 SP5
1.0.27.2-15.1
fixed
suse enterprise server 12
1.0.27.2-11.4
fixed
suse enterprise server 12 SP2
1.0.27.2-11.4
fixed
suse enterprise server 12 SP3
1.0.27.2-15.1
fixed
suse enterprise server 12 SP4
1.0.27.2-15.1
fixed
suse enterprise server 12 SP5
1.0.27.2-15.1
fixed
libasound2
suse enterprise desktop 15
1.1.5-4.22
fixed
suse enterprise desktop 15 SP1
1.1.5-6.6.1
fixed
suse enterprise desktop 15 SP2
1.1.5-6.6.1
fixed
suse enterprise sap 12 SP5
1.0.27.2-15.1
fixed
suse enterprise sap 15
1.1.5-4.22
fixed
suse enterprise sap 15 SP1
1.1.5-6.6.1
fixed
suse enterprise sap 15 SP2
1.1.5-6.6.1
fixed
suse enterprise server 12
1.0.27.2-11.4
fixed
suse enterprise server 12 SP2
1.0.27.2-11.4
fixed
suse enterprise server 12 SP3
1.0.27.2-15.1
fixed
suse enterprise server 12 SP4
1.0.27.2-15.1
fixed
suse enterprise server 12 SP5
1.0.27.2-15.1
fixed
suse enterprise server 15
1.1.5-4.22
fixed
suse enterprise server 15 SP1
1.1.5-6.6.1
fixed
suse enterprise server 15 SP2
1.1.5-6.6.1
fixed
libasound2-32bit
suse enterprise desktop 15
1.1.5-4.22
fixed
suse enterprise desktop 15 SP1
1.1.5-6.6.1
fixed
suse enterprise desktop 15 SP2
1.1.5-6.6.1
fixed
suse enterprise sap 12 SP5
1.0.27.2-15.1
fixed
suse enterprise sap 15
1.1.5-4.22
fixed
suse enterprise sap 15 SP1
1.1.5-6.6.1
fixed
suse enterprise sap 15 SP2
1.1.5-6.6.1
fixed
suse enterprise server 12
1.0.27.2-11.10
fixed
suse enterprise server 12 SP2
1.0.27.2-11.10
fixed
suse enterprise server 12 SP3
1.0.27.2-15.1
fixed
suse enterprise server 12 SP4
1.0.27.2-15.1
fixed
suse enterprise server 12 SP5
1.0.27.2-15.1
fixed
suse enterprise server 15
1.1.5-4.22
fixed
suse enterprise server 15 SP1
1.1.5-6.6.1
fixed
suse enterprise server 15 SP2
1.1.5-6.6.1
fixed