CVE-2020-11931
published 2020-05-15CVE-2020-11931: An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access…
PriorityP411low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.33%
25.0th percentile
An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback or audio-record via unloading the pulseaudio snap policy module. This issue affects: pulseaudio 1:8.0 versions prior to 1:8.0-0ubuntu3.12; 1:11.1 versions prior to 1:11.1-1ubuntu7.7; 1:13.0 versions prior to 1:13.0-1ubuntu1.2; 1:13.99.1 versions prior to 1:13.99.1-1ubuntu3.2;
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | pulseaudio | >= 1:11.1 < 1:11.1-1ubuntu7.7 | 1:11.1-1ubuntu7.7 |
| canonical | pulseaudio | >= 1:13.0 < 1:13.0-1ubuntu1.2 | 1:13.0-1ubuntu1.2 |
| canonical | pulseaudio | >= 1:13.99.1 < 1:13.99.1-1ubuntu3.2 | 1:13.99.1-1ubuntu3.2 |
| canonical | pulseaudio | >= 1:8.0 < 1:8.0-0ubuntu3.12 | 1:8.0-0ubuntu3.12 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| pulseaudio | pulseaudio | <= 1.8.0 | — |
| pulseaudio | pulseaudio | >= 0 < 1:8.0-0ubuntu3.12 | 1:8.0-0ubuntu3.12 |
| pulseaudio | pulseaudio | >= 0 < 1:11.1-1ubuntu7.7 | 1:11.1-1ubuntu7.7 |
| pulseaudio | pulseaudio | >= 0 < 1:13.99.1-1ubuntu3.2 | 1:13.99.1-1ubuntu3.2 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m777-7jfr-8wgh: An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended acce
ghsa_unreviewed·2022-05-24
CVE-2020-11931 [LOW] GHSA-m777-7jfr-8wgh: An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended acce
An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback or audio-record via unloading the pulseaudio snap policy module. This issue affects: pulseaudio 1:8.0 versions prior to 1:8.0-0ubuntu3.12; 1:11.1 versions prior to 1:11.1-1ubuntu7.7; 1:13.0 versions prior to 1:13.0-1ubuntu1.2; 1:13.99.1 versions prior to 1:13.99.1-1ubuntu3.2;
OSV
CVE-2020-11931: An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended acce
osv·2020-04-16·CVSS 3.3
CVE-2020-11931 [LOW] CVE-2020-11931: An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended acce
An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback or audio-record via unloading the pulseaudio snap policy module. This issue affects: pulseaudio 1:8.0 versions prior to 1:8.0-0ubuntu3.12; 1:11.1 versions prior to 1:11.1-1ubuntu7.7; 1:13.0 versions prior to 1:13.0-1ubuntu1.2; 1:13.99.1 versions prior to 1:13.99.1-1ubuntu3.2;
Ubuntu
PulseAudio vulnerability
vendor_ubuntu·2020-05-12
CVE-2020-11931 PulseAudio vulnerability
Title: PulseAudio vulnerability
Summary: PulseAudio could allow unintended access to snap packages.
PulseAudio in Ubuntu contains additional functionality to mediate audio
recording for snap packages and it was discovered that this functionality
did not mediate PulseAudio module unloading. An attacker-controlled snap
with only the audio-playback interface connected could exploit this to
bypass access controls and record audio.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-05-15
Published