Vulnerability Name:

CVE-2009-1894 (CCN-51804)

Assigned:2009-07-16
Published:2009-07-16
Updated:2023-02-13
Summary:
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.9 Medium (CCN CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
5.1 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Consequences:Gain Privileges
References:Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: MITRE
Type: CNA
CVE-2009-1894

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: Akita Software Security Web site
PulseAudio local race condition privilege escalation vulnerability

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: DEBIAN
Type: DSA-1838
pulseaudio -- privilege escalation

Source: CCN
Type: GLSA-200907-13
PulseAudio: Local privilege escalation

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: OSVDB ID: 55923
Linux Kernel drivers/net/tun.c tun_char_poll() Function NULL Dereference Local Privilege Escalation

Source: CCN
Type: OSVDB ID: 56104
PulseAudio LD_BIND_NOW /proc/self/exe Symlink Local Privilege Escalation

Source: CCN
Type: PulseAudio Web site
PulseAudio - Trac

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: BID-35721
PulseAudio setuid Local Privilege Escalation Vulnerability

Source: secalert@redhat.com
Type: Exploit, Patch
secalert@redhat.com

Source: CCN
Type: USN-804-1
PulseAudio vulnerability

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: Exploit, Patch
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: XF
Type: UNKNOWN
pulseaudio-suid-privilege-escalation(51804)

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/a:pulseaudio:pulseaudio:0.9.5:*:*:*:*:*:*:*
  • OR cpe:/a:pulseaudio:pulseaudio:0.9.6:*:*:*:*:*:*:*
  • OR cpe:/a:pulseaudio:pulseaudio:0.9.8:*:*:*:*:*:*:*
  • OR cpe:/a:pulseaudio:pulseaudio:0.9.9:*:*:*:*:*:*:*
  • OR cpe:/a:pulseaudio:pulseaudio:0.9.10:*:*:*:*:*:*:*
  • OR cpe:/a:pulseaudio:pulseaudio:0.9.14:*:*:*:*:*:*:*
  • AND
  • cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:x86_64:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:2008.1:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu:8.04::lts:*:*:*:*:*
  • OR cpe:/o:mandriva:linux:2009.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandriva:linux:2009.0:-:x86_64:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:5.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandriva:linux:2009.1:*:*:*:*:*:*:*
  • OR cpe:/o:mandriva:linux:2009.1:*:*:*:x86_64:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:13788
    P
    USN-804-1 -- pulseaudio vulnerability
    2014-06-30
    oval:org.mitre.oval:def:7658
    P
    DSA-1838 pulseaudio -- privilege escalation
    2014-06-23
    oval:org.mitre.oval:def:12996
    P
    DSA-1838-1 pulseaudio -- privilege escalation
    2014-06-23
    oval:org.debian:def:1838
    V
    privilege escalation
    2009-07-18
    BACK
    pulseaudio pulseaudio 0.9.5
    pulseaudio pulseaudio 0.9.6
    pulseaudio pulseaudio 0.9.8
    pulseaudio pulseaudio 0.9.9
    pulseaudio pulseaudio 0.9.10
    pulseaudio pulseaudio 0.9.14
    gentoo linux *
    mandrakesoft mandrake linux 2008.1 x86_64
    mandrakesoft mandrake linux 2008.1
    canonical ubuntu 8.04
    mandriva linux 2009.0
    mandriva linux 2009.0 -
    debian debian linux 5.0
    mandriva linux 2009.1
    mandriva linux 2009.1