Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Ubuntu modifications to pulseaudio to provide snap security enforcement could be unloaded
Vulnerability Description
An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback or audio-record via unloading the pulseaudio snap policy module. This issue affects: pulseaudio 1:8.0 versions prior to 1:8.0-0ubuntu3.12; 1:11.1 versions prior to 1:11.1-1ubuntu7.7; 1:13.0 versions prior to 1:13.0-1ubuntu1.2; 1:13.99.1 versions prior to 1:13.99.1-1ubuntu3.2;
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
访问控制不恰当
Vulnerability Title
PulseAudio 访问控制错误漏洞
Vulnerability Description
PulseAudio是一款用于POSIX OS的开源音频系统。该系统主要用于音频传输等。 PulseAudio中存在访问控制错误漏洞。该漏洞源于网络系统或产品未正确限制来自未授权角色的资源访问。以下产品及版本受到影响:PulseAudio 1:8.0-0ubuntu3.12之前的1:8.0版本,1:11.1-1ubuntu7.7之前的1:11.1版本,1:13.0-1ubuntu1.2之前的1:13.0版本,1:13.99.1-1ubuntu3.2之前的1:13.99.1版本。
CVSS Information
N/A
Vulnerability Type
N/A