2.1
CVSSv2

CVE-2010-1149

Published: 12/04/2010 Updated: 13/04/2010
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

probers/udisks-dm-export.c in udisks prior to 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discover encryption keys by (1) running a certain udevadm command or (2) reading a certain file under /dev/.udev/db/.

Vulnerable Product Search on Vulmon Subscribe to Product

freedesktop udisks

Vendor Advisories

Debian Bug report logs - #576687 udisks - Exports dm table data Package: udisks; Maintainer for udisks is Utopia Maintenance Team <pkg-utopia-maintainers@listsaliothdebianorg>; Source for udisks is src:udisks (PTS, buildd, popcon) Reported by: Bastian Blank <waldi@debianorg> Date: Tue, 6 Apr 2010 14:42:05 UTC S ...