First published: Tue Apr 06 2010(Updated: )
probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discover encryption keys by (1) running a certain udevadm command or (2) reading a certain file under /dev/.udev/db/.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME Disks | <=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-1149 is rated as medium due to the potential exposure of encryption keys.
To fix CVE-2010-1149, upgrade udisks to version 1.0.1 or later.
CVE-2010-1149 affects systems running udisks versions prior to 1.0.1.
Yes, CVE-2010-1149 can lead to data breaches as local users may access sensitive encryption keys.
Local users on systems running vulnerable versions of udisks are impacted by CVE-2010-1149.