Dit bericht is nog niet vertaald

[USN-573-1] PulseAudio vulnerability

Ubuntu Security Notice USN-573-1           January 31, 2008
pulseaudio vulnerability
CVE-2008-0008
Kwetsbare Ubuntu versies:

Ubuntu 7.04
Ubuntu 7.10

Kwetsbare pakketten:

Ubuntu 7.04
pulseaudio 0.9.5-5ubuntu4.2
Ubuntu 7.10
pulseaudio 0.9.6-1ubuntu2.1

In general, a standard system upgrade is sufficient to effect the necessary changes.

It was discovered that PulseAudio did not properly drop privileges when running as a daemon. Local users may be able to exploit this and gain privileges. The default Ubuntu configuration is not affected.