DEBIAN-CVE-2019-13351

Source
https://security-tracker.debian.org/tracker/CVE-2019-13351
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2019-13351.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2019-13351
Upstream
Published
2019-07-05T20:15:14Z
Modified
2026-09-21T07:02:19Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 (as distributed with alsa-plugins 1.1.7 and later) has a "double file descriptor close" issue during a failed connection attempt when jackd2 is not running. Exploitation success depends on multithreaded timing of that double close, which can result in unintended information disclosure, crashes, or file corruption due to having the wrong file associated with the file descriptor.

References

Affected packages

Debian:12 / jackd2

Package

Name
jackd2
Purl
pkg:deb/debian/jackd2?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.9.14~dfsg-0.1

Ecosystem specific

{
    "urgency":  "low"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2019-13351.json"

Debian:13 / jackd2

Package

Name
jackd2
Purl
pkg:deb/debian/jackd2?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.9.14~dfsg-0.1

Ecosystem specific

{
    "urgency":  "low"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2019-13351.json"

Debian:14 / jackd2

Package

Name
jackd2
Purl
pkg:deb/debian/jackd2?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.9.14~dfsg-0.1

Ecosystem specific

{
    "urgency":  "low"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2019-13351.json"