CVE-2020-15710: Potential double-free in pulseaudio
Published Nov 19, 2020
·Updated
Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. The modargs variable may be freed twice in the fail condition in src/modules/bluetooth/module-bluez5-device.c and src/modules/bluetooth/module-bluez5-device.c. Fixed in 1:8.0-0ubuntu3.14.
Affected Software
17 affected components
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu1
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu2
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.1
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.2
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.3
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.4
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.5
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.6
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.7
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.8
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.9
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.10
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.11
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.12
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu4
Canonical Ubuntu Linux=16.04
Event History
Nov 19, 2020
CVE Published
via MITRE·02:30 AM
Data Sourced
via MITRE·02:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-15710?
CVE-2020-15710 is considered to have a medium severity due to potential memory leaks and crashing.
2
How do I fix CVE-2020-15710?
To fix CVE-2020-15710, update PulseAudio to the latest version that resolves the double free issue.
3
What systems are affected by CVE-2020-15710?
CVE-2020-15710 affects PulseAudio versions 1:8.0-0ubuntu1 to 1:8.0-0ubuntu4.
4
Can CVE-2020-15710 be exploited remotely?
No, CVE-2020-15710 requires local access to exploit the vulnerability.
5
What are the consequences of CVE-2020-15710?
The consequences of CVE-2020-15710 include potential memory leaks or application crashes.