cbcvebase.
CVE-2020-16123
published 2020-12-04

CVE-2020-16123: An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a client connection from a snap as coming…

medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a client connection from a snap as coming from a snap if SCM_CREDENTIALS were missing, allowing the snap to connect to PulseAudio without proper confinement. This could be exploited by an attacker to expose sensitive information. Fixed in 1:13.99.3-1ubuntu2, 1:13.99.2-1ubuntu2.1, 1:13.99.1-1ubuntu3.8, 1:11.1-1ubuntu7.11, and 1:8.0-0ubuntu3.15.

Affected

13 ranges
VendorProductVersion rangeFixed in
canonicalpulseaudio>= 1:11.1-1 < 1:11.1-1ubuntu7.111:11.1-1ubuntu7.11
canonicalpulseaudio>= 1:13.99.1-1 < 1:13.99.1-1ubuntu3.81:13.99.1-1ubuntu3.8
canonicalpulseaudio>= 1:13.99.2-1 < 1:13.99.2-1ubuntu2.11:13.99.2-1ubuntu2.1
canonicalpulseaudio>= 1:13.99.3-1 < 1:13.99.3-1ubuntu21:13.99.3-1ubuntu2
canonicalpulseaudio>= 1:8.0-0 < 1:8.0-0ubuntu3.151:8.0-0ubuntu3.15
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianpulseaudio
pulseaudiopulseaudio>= 0 < 1:8.0-0ubuntu3.151:8.0-0ubuntu3.15
pulseaudiopulseaudio>= 0 < 1:11.1-1ubuntu7.111:11.1-1ubuntu7.11
pulseaudiopulseaudio>= 0 < 1:13.99.1-1ubuntu3.81:13.99.1-1ubuntu3.8

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
osv4.7MEDIUM