[Secure-testing-team] Pulseaudio CVS-2008-0008
Sjoerd Simons
sjoerd at luon.net
Thu Jan 24 12:31:05 UTC 2008
Hi,
I've just uploaded pulseaudio 0.9.9-1 to unstable. This fixes CVE-2008-0008,
pulseaudio didn't check the return codes of setuid, which potentially made it
possible for a user to prevent it from dropping permissions.
While 0.9.9 is a new upstream release, but the only change since the 0.9.8 is
the security fix. So i opted for just uploading the new release instead of
adding an extra patch.
Sjoerd
--
In order to discover who you are, first learn who everybody else is;
you're what's left.
More information about the Secure-testing-team
mailing list