CVE-2009-1894

EUVD-2009-1889
Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link, related to the application setting LD_BIND_NOW to 1, and then calling execv on the target of the /proc/self/exe symlink.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
Affected Products (NVD)
VendorProductVersion
pulseaudiopulseaudio
0.9.9
pulseaudiopulseaudio
0.9.10
pulseaudiopulseaudio
0.9.14
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pulseaudio
bookworm
16.1+dfsg1-2
fixed
bullseye
14.2-2
fixed
etch
not-affected
sid
16.1+dfsg1-5.1
fixed
trixie
16.1+dfsg1-5.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pulseaudio
dapper
dne
hardy
Fixed 0.9.10-1ubuntu1.1
released
intrepid
Fixed 0.9.10-2ubuntu9.4
released
jaunty
Fixed 1:0.9.14-0ubuntu20.2
released
References