Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long mount point.
Bastian Blank reported: [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=576687
an information leak in the way udisks's disks and storage device management daemon passed sensitive device mapper table information to userspace processes via the udev interface. Local attacker could use this flaw to conduct subsequent unauthorized operations on storage device(s), which should be otherwise protected by encryption / luks passphrase knowledge.
Upstream bug report: [2] https://bugs.freedesktop.org/showbug.cgi?id=27494
Upstream patch: [3] http://cgit.freedesktop.org/udisks/commit/?id=0fcc7cb3b66f23fac53ae08647aa0007a2bd56c4
References: [4] https://bugzilla.novell.com/showbug.cgi?id=594261
CVE Request: [5] http://www.openwall.com/lists/oss-security/2010/04/06/5