CVE-2009-1894
Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link, related to the application setting LD_BIND_NOW to 1, and then calling execv on the target of the /proc/self/exe symlink.
- Affected products
- Pulseaudio
- Pulseaudio
- = 0.9.9, 0.9.10, 0.9.14
- Fix
- Available
- CVSS 2.0
- 7.2 HIGH
- EPSS
- 0.7% (52th percentile)
- Weakness
- CWE-362
- NVD status
- Modified
- Published
- 2009-07-17
CVE-2009-1894 at NVD
7 known exploits for CVE-2009-1894
Proof-of-concept code and exploit modules indexed by Sploitus
GNU C library dynamic linker $ORIGIN expansion Vulnerability
GNU C library dynamic linker $ORIGIN expansion Vulnerability
GNU C Library Dynamic Linker $ORIGIN Expansion Vulnerability
GNU C library dynamic linker - $ORIGIN Expansion
PulseAudio setuid - Local Privilege Escalation
PulseAudio setuid (Ubuntu 9.04 / Slackware 12.2.0) - Local Privilege Escalation
Linux Kernel tun_chr_pool()函数空指针引用漏洞