CVE-2010-1149

probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discover encryption keys by (1) running a certain udevadm command or (2) reading a certain file under /dev/.udev/db/.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freedesktop:udisks:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:13

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=576687 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=576687 -
References () http://cgit.freedesktop.org/udisks/commit/?id=0fcc7cb3b66f23fac53ae08647aa0007a2bd56c4 - () http://cgit.freedesktop.org/udisks/commit/?id=0fcc7cb3b66f23fac53ae08647aa0007a2bd56c4 -
References () http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039060.html - () http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039060.html -
References () http://secunia.com/advisories/39332 - Vendor Advisory () http://secunia.com/advisories/39332 - Vendor Advisory
References () http://www.securityfocus.com/bid/39265 - () http://www.securityfocus.com/bid/39265 -
References () https://bugs.freedesktop.org/show_bug.cgi?id=27494 - () https://bugs.freedesktop.org/show_bug.cgi?id=27494 -
References () https://bugzilla.novell.com/show_bug.cgi?id=594261 - () https://bugzilla.novell.com/show_bug.cgi?id=594261 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=580005 - () https://bugzilla.redhat.com/show_bug.cgi?id=580005 -
References () https://launchpad.net/bugs/556651 - () https://launchpad.net/bugs/556651 -

Information

Published : 2010-04-12 18:30

Updated : 2024-11-21 01:13


NVD link : CVE-2010-1149

Mitre link : CVE-2010-1149

CVE.ORG link : CVE-2010-1149


JSON object : View

Products Affected

freedesktop

  • udisks
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor