First published: Wed Apr 07 2010(Updated: )
Bastian Blank reported: [1] <a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=576687">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=576687</a> an information leak in the way udisks's disks and storage device management daemon passed sensitive device mapper table information to userspace processes via the udev interface. Local attacker could use this flaw to conduct subsequent unauthorized operations on storage device(s), which should be otherwise protected by encryption / luks passphrase knowledge. Upstream bug report: [2] <a href="https://bugs.freedesktop.org/show_bug.cgi?id=27494">https://bugs.freedesktop.org/show_bug.cgi?id=27494</a> Upstream patch: [3] <a href="http://cgit.freedesktop.org/udisks/commit/?id=0fcc7cb3b66f23fac53ae08647aa0007a2bd56c4">http://cgit.freedesktop.org/udisks/commit/?id=0fcc7cb3b66f23fac53ae08647aa0007a2bd56c4</a> References: [4] <a href="https://bugzilla.novell.com/show_bug.cgi?id=594261">https://bugzilla.novell.com/show_bug.cgi?id=594261</a> CVE Request: [5] <a href="http://www.openwall.com/lists/oss-security/2010/04/06/5">http://www.openwall.com/lists/oss-security/2010/04/06/5</a>
Affected Software | Affected Version | How to fix |
---|---|---|
UDisks |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-580005 is classified as a medium risk due to potential information leakage.
To fix REDHAT-BUG-580005, update your UDisks software to the latest version that addresses this vulnerability.
REDHAT-BUG-580005 is categorized as an information leak vulnerability in the UDisks disk management daemon.
The affected software for REDHAT-BUG-580005 is the UDisks disk management tool from freedesktop.
Attackers exploiting REDHAT-BUG-580005 may gain access to sensitive device mapper table information.