DEBIAN-CVE-2008-0008

Source
https://security-tracker.debian.org/tracker/CVE-2008-0008
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-0008.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2008-0008
Upstream
Downstream
Published
2008-01-29T00:00:00Z
Modified
2026-09-01T20:02:50Z
Summary
[none]
Details

The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail via attacks such as resource exhaustion.

References

Affected packages

Debian:12 / pulseaudio

Package

Name
pulseaudio
Purl
pkg:deb/debian/pulseaudio?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.9.9-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-0008.json"

Debian:13 / pulseaudio

Package

Name
pulseaudio
Purl
pkg:deb/debian/pulseaudio?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.9.9-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-0008.json"

Debian:14 / pulseaudio

Package

Name
pulseaudio
Purl
pkg:deb/debian/pulseaudio?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.9.9-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-0008.json"