Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-0008
Description:The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail via attacks such as resource exhaustion.
Test IDs: 1.3.6.1.4.1.25623.1.0.60384   1.3.6.1.4.1.25623.1.0.60269   1.3.6.1.4.1.25623.1.0.60265   1.3.6.1.4.1.25623.1.0.840337   1.3.6.1.4.1.25623.1.0.860694   1.3.6.1.4.1.25623.1.0.860153   1.3.6.1.4.1.25623.1.0.60294   1.3.6.1.4.1.25623.1.0.60259   1.3.6.1.4.1.25623.1.0.60266  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-0008
BugTraq ID: 27449
http://www.securityfocus.com/bid/27449
Debian Security Information: DSA-1476 (Google Search)
http://www.debian.org/security/2008/dsa-1476
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00852.html
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00869.html
http://security.gentoo.org/glsa/glsa-200802-07.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:027
https://tango.0pointer.de/pipermail/pulseaudio-discuss/2008-January/001228.html
http://secunia.com/advisories/28608
http://secunia.com/advisories/28623
http://secunia.com/advisories/28738
http://secunia.com/advisories/28952
http://www.ubuntu.com/usn/usn-573-1
http://www.vupen.com/english/advisories/2008/0283
XForce ISS Database: pulseaudio-padroproot-privilege-escalation(39992)
https://exchange.xforce.ibmcloud.com/vulnerabilities/39992




© 1998-2025 E-Soft Inc. All rights reserved.