Summary
The remote host is missing an update to pulseaudio announced via advisory USN-804-1.
Solution
The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 8.04 LTS:
pulseaudio 0.9.10-1ubuntu1.1
Ubuntu 8.10:
pulseaudio 0.9.10-2ubuntu9.4
Ubuntu 9.04:
pulseaudio 1:0.9.14-0ubuntu20.2
In general, a standard system upgrade is sufficient to effect the necessary changes.
https://secure1.securityspace.com/smysecure/catid.html?in=USN-804-1
Insight
Tavis Ormandy and Yorick Koster discovered that PulseAudio did not safely re-execute itself. A local attacker could exploit this to gain root privileges.
Severity
Classification
-
CVE CVE-2009-1894 -
CVSS Base Score: 7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities