CVE-2020-15710
Potential double-free in pulseaudio
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. The modargs variable may be freed twice in the fail condition in src/modules/bluetooth/module-bluez5-device.c and src/modules/bluetooth/module-bluez5-device.c. Fixed in 1:8.0-0ubuntu3.14.
Una potencial doble liberación en el módulo Bluez 5 de PulseAudio, podría permitir a un atacante local perder memoria o bloquear el programa. La variable modargs puede ser liberada dos veces en una condición de fallo en los archivos src/modules/bluetooth/module-bluez5-device.c y src/modules/bluetooth/module-bluez5-device.c. Corregido en la versión 1:8.0-0ubuntu3.14
Ratchanan Srirattanamet discovered that an Ubuntu-specific patch caused PulseAudio to incorrectly handle memory under certain error conditions in the Bluez 5 module. An attacker could use this issue to cause PulseAudio to crash, resulting in a denial of service, or possibly execute arbitrary code.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-07-14 CVE Reserved
- 2020-09-18 CVE Published
- 2024-09-17 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-415: Double Free
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://launchpad.net/bugs/1884738 | 2020-12-16 | |
https://ubuntu.com/USN-4519-1 | 2020-12-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pulseaudio Project Search vendor "Pulseaudio Project" | Pulseaudio Search vendor "Pulseaudio Project" for product "Pulseaudio" | 1:8.0-0ubuntu1 Search vendor "Pulseaudio Project" for product "Pulseaudio" and version "1:8.0-0ubuntu1" | - |
Affected
| in | Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Safe
|
Pulseaudio Project Search vendor "Pulseaudio Project" | Pulseaudio Search vendor "Pulseaudio Project" for product "Pulseaudio" | 1:8.0-0ubuntu2 Search vendor "Pulseaudio Project" for product "Pulseaudio" and version "1:8.0-0ubuntu2" | - |
Affected
| in | Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Safe
|
Pulseaudio Project Search vendor "Pulseaudio Project" | Pulseaudio Search vendor "Pulseaudio Project" for product "Pulseaudio" | 1:8.0-0ubuntu3 Search vendor "Pulseaudio Project" for product "Pulseaudio" and version "1:8.0-0ubuntu3" | - |
Affected
| in | Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Safe
|
Pulseaudio Project Search vendor "Pulseaudio Project" | Pulseaudio Search vendor "Pulseaudio Project" for product "Pulseaudio" | 1:8.0-0ubuntu3.1 Search vendor "Pulseaudio Project" for product "Pulseaudio" and version "1:8.0-0ubuntu3.1" | - |
Affected
| in | Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Safe
|
Pulseaudio Project Search vendor "Pulseaudio Project" | Pulseaudio Search vendor "Pulseaudio Project" for product "Pulseaudio" | 1:8.0-0ubuntu3.2 Search vendor "Pulseaudio Project" for product "Pulseaudio" and version "1:8.0-0ubuntu3.2" | - |
Affected
| in | Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Safe
|
Pulseaudio Project Search vendor "Pulseaudio Project" | Pulseaudio Search vendor "Pulseaudio Project" for product "Pulseaudio" | 1:8.0-0ubuntu3.3 Search vendor "Pulseaudio Project" for product "Pulseaudio" and version "1:8.0-0ubuntu3.3" | - |
Affected
| in | Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Safe
|
Pulseaudio Project Search vendor "Pulseaudio Project" | Pulseaudio Search vendor "Pulseaudio Project" for product "Pulseaudio" | 1:8.0-0ubuntu3.4 Search vendor "Pulseaudio Project" for product "Pulseaudio" and version "1:8.0-0ubuntu3.4" | - |
Affected
| in | Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Safe
|
Pulseaudio Project Search vendor "Pulseaudio Project" | Pulseaudio Search vendor "Pulseaudio Project" for product "Pulseaudio" | 1:8.0-0ubuntu3.5 Search vendor "Pulseaudio Project" for product "Pulseaudio" and version "1:8.0-0ubuntu3.5" | - |
Affected
| in | Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Safe
|
Pulseaudio Project Search vendor "Pulseaudio Project" | Pulseaudio Search vendor "Pulseaudio Project" for product "Pulseaudio" | 1:8.0-0ubuntu3.6 Search vendor "Pulseaudio Project" for product "Pulseaudio" and version "1:8.0-0ubuntu3.6" | - |
Affected
| in | Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Safe
|
Pulseaudio Project Search vendor "Pulseaudio Project" | Pulseaudio Search vendor "Pulseaudio Project" for product "Pulseaudio" | 1:8.0-0ubuntu3.7 Search vendor "Pulseaudio Project" for product "Pulseaudio" and version "1:8.0-0ubuntu3.7" | - |
Affected
| in | Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Safe
|
Pulseaudio Project Search vendor "Pulseaudio Project" | Pulseaudio Search vendor "Pulseaudio Project" for product "Pulseaudio" | 1:8.0-0ubuntu3.8 Search vendor "Pulseaudio Project" for product "Pulseaudio" and version "1:8.0-0ubuntu3.8" | - |
Affected
| in | Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Safe
|
Pulseaudio Project Search vendor "Pulseaudio Project" | Pulseaudio Search vendor "Pulseaudio Project" for product "Pulseaudio" | 1:8.0-0ubuntu3.9 Search vendor "Pulseaudio Project" for product "Pulseaudio" and version "1:8.0-0ubuntu3.9" | - |
Affected
| in | Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Safe
|
Pulseaudio Project Search vendor "Pulseaudio Project" | Pulseaudio Search vendor "Pulseaudio Project" for product "Pulseaudio" | 1:8.0-0ubuntu3.10 Search vendor "Pulseaudio Project" for product "Pulseaudio" and version "1:8.0-0ubuntu3.10" | - |
Affected
| in | Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Safe
|
Pulseaudio Project Search vendor "Pulseaudio Project" | Pulseaudio Search vendor "Pulseaudio Project" for product "Pulseaudio" | 1:8.0-0ubuntu3.11 Search vendor "Pulseaudio Project" for product "Pulseaudio" and version "1:8.0-0ubuntu3.11" | - |
Affected
| in | Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Safe
|
Pulseaudio Project Search vendor "Pulseaudio Project" | Pulseaudio Search vendor "Pulseaudio Project" for product "Pulseaudio" | 1:8.0-0ubuntu3.12 Search vendor "Pulseaudio Project" for product "Pulseaudio" and version "1:8.0-0ubuntu3.12" | - |
Affected
| in | Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Safe
|
Pulseaudio Project Search vendor "Pulseaudio Project" | Pulseaudio Search vendor "Pulseaudio Project" for product "Pulseaudio" | 1:8.0-0ubuntu4 Search vendor "Pulseaudio Project" for product "Pulseaudio" and version "1:8.0-0ubuntu4" | - |
Affected
| in | Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | lts |
Safe
|