probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discover encryption keys by (1) running a certain udevadm command or (2) reading a certain file under /dev/.udev/db/.
References
Configurations
History
No history.
Information
Published : 2010-04-12 18:30
Updated : 2025-04-11 00:51
NVD link : CVE-2010-1149
Mitre link : CVE-2010-1149
CVE.ORG link : CVE-2010-1149
JSON object : View
Products Affected
freedesktop
- udisks
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor