suse · CVE-2008-0008

Quick triage

Priority: high Published: 2021-05-30 12:41:24 UTC Updated: 2026-04-18 20:29:39 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2008-0008 severity important: SUSE including 67 source package names (libpulse-browse0-0.9.21-1.5.26, libpulse-browse0-0.9.23-0.17.1, …), 79 product×package rows across 7 product lines (SUSE Linux Enterprise Server 11 SP1, SUSE Linux Enterprise Server 11 SP2, … (7 product lines)): Fixed 79.

Description:

The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail via attacks such as resource exhaustion.

cvelogic Threat Intelligence