First published: Wed Jan 24 2024(Updated: )
Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
PipeWire |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4964 has been assigned a high severity rating due to the potential for unauthorized microphone access.
CVE-2022-4964 allows unauthorized access to the microphone, which can lead to privacy breaches for users.
To remediate CVE-2022-4964, users should update their pipewire-pulse package to the latest version that resolves this issue.
CVE-2022-4964 affects specific versions of the Ubuntu pipewire-pulse package before the patch is applied.
The best workaround for CVE-2022-4964 is to temporarily disable microphone access in the snap settings until an update is applied.