First published: Tue Jul 07 2009(Updated: )
Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link, related to the application setting LD_BIND_NOW to 1, and then calling execv on the target of the /proc/self/exe symlink.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
PulseAudio | =0.9.9 | |
PulseAudio | =0.9.10 | |
PulseAudio | =0.9.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1894 is classified as a high severity vulnerability due to its potential to allow local users to gain elevated privileges.
To fix CVE-2009-1894, upgrade PulseAudio to a version later than 0.9.14 where the race condition has been addressed.
PulseAudio versions 0.9.9, 0.9.10, and 0.9.14 are affected by CVE-2009-1894.
CVE-2009-1894 is a race condition vulnerability that can be exploited to achieve privilege escalation.
Any system running the affected versions of PulseAudio, typically found in Unix-like operating systems, is vulnerable to CVE-2009-1894.