CVE-2008-0008

Source
https://nvd.nist.gov/vuln/detail/CVE-2008-0008
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2008-0008.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2008-0008
Related
Published
2008-01-29T00:00:00Z
Modified
2024-11-21T00:40:57Z
Summary
[none]
Details

The padroproot function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail via attacks such as resource exhaustion.

References

Affected packages

Debian:11 / pulseaudio

Package

Name
pulseaudio
Purl
pkg:deb/debian/pulseaudio?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.9-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / pulseaudio

Package

Name
pulseaudio
Purl
pkg:deb/debian/pulseaudio?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.9-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / pulseaudio

Package

Name
pulseaudio
Purl
pkg:deb/debian/pulseaudio?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.9-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}