CVE-2009-1894
HIGH 7.2EPSS 0.7%
Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link, related to the application setting LD_BIND_NOW to 1, and then calling execv on the target of the /proc/self/exe symlink.
- CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 0.74% chance of exploitation in the next 30 days, 52th percentile
- Published
- 2009-07-17
- Updated
- 2024-08-07