CVE-2009-1894
pulseaudio - privilege escalation
EPSS 0.74%
Description
Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link, related to the application setting LD_BIND_NOW to 1, and then calling execv on the target of the /proc/self/exe symlink.
How to fix CVE-2009-1894
To remediate CVE-2009-1894, upgrade the affected package to a fixed version below.
- Debian/pulseaudio—upgrade to 0.9.15-4.1 or later
- Debian/pulseaudio—upgrade to 0.9.10-3+lenny1 or later
Is CVE-2009-1894 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.9.15-4.1
- from 0, < 0.9.10-3+lenny1