CVE-2009-1894

Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link, related to the application setting LD_BIND_NOW to 1, and then calling execv on the target of the /proc/self/exe symlink.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 29%
VendorProductVersion
pulseaudiopulseaudio
0.9.9
pulseaudiopulseaudio
0.9.10
pulseaudiopulseaudio
0.9.14
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pulseaudio
bullseye
14.2-2
fixed
etch
not-affected
bookworm
16.1+dfsg1-2
fixed
sid
16.1+dfsg1-5.1
fixed
trixie
16.1+dfsg1-5.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pulseaudio
jaunty
Fixed 1:0.9.14-0ubuntu20.2
released
intrepid
Fixed 0.9.10-2ubuntu9.4
released
hardy
Fixed 0.9.10-1ubuntu1.1
released
dapper
dne
References