probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discover encryption keys by (1) running a certain udevadm command or (2) reading a certain file under /dev/.udev/db/.
References
Configurations
Information
Published : 2010-04-12 11:30
Updated : 2010-04-12 21:00
NVD link : CVE-2010-1149
Mitre link : CVE-2010-1149
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
freedesktop
- udisks