3.3
CVSSv3

CVE-2020-11931

Published: 15/05/2020 Updated: 19/05/2020
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback or audio-record via unloading the pulseaudio snap policy module. This issue affects: pulseaudio 1:8.0 versions before 1:8.0-0ubuntu3.12; 1:11.1 versions before 1:11.1-1ubuntu7.7; 1:13.0 versions before 1:13.0-1ubuntu1.2; 1:13.99.1 versions before 1:13.99.1-1ubuntu3.2;

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pulseaudio pulseaudio

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 19.10

canonical ubuntu linux 20.04

Vendor Advisories

PulseAudio could allow unintended access to snap packages ...