[Secure-testing-team] Pulseaudio CVS-2008-0008

Sjoerd Simons sjoerd at luon.net
Thu Jan 24 12:31:05 UTC 2008


Hi,

  I've just uploaded pulseaudio 0.9.9-1 to unstable. This fixes CVE-2008-0008,
  pulseaudio didn't check the return codes of setuid, which potentially made it
  possible for a user to prevent it from dropping permissions.

  While 0.9.9 is a new upstream release, but the only change since the 0.9.8 is
  the security fix. So i opted for just uploading the new release instead of
  adding an extra patch.

  Sjoerd
-- 
In order to discover who you are, first learn who everybody else is;
you're what's left.



More information about the Secure-testing-team mailing list