probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev...
Vulnerability Description
probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discover encryption keys by (1) running a certain udevadm command or (2) reading a certain file under /dev/.udev/db/.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-1149
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039060.html
- https://bugzilla.novell.com/show_bug.cgi?id=594261
- https://launchpad.net/bugs/556651
- https://bugs.freedesktop.org/show_bug.cgi?id=27494
- http://secunia.com/advisories/39332
- http://www.securityfocus.com/bid/39265
- https://bugzilla.redhat.com/show_bug.cgi?id=580005
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=576687
- http://cgit.freedesktop.org/udisks/commit/?id=0fcc7cb3b66f23fac53ae08647aa0007a2bd56c4
More from freedesktop
View All →Affected Vendor
freedesktop
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.