CVE Vulnerabilities

CVE-2020-15710

Double Free

Published: Nov 19, 2020 | Modified: Dec 16, 2020
CVSS 3.x
6.1
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. The modargs variable may be freed twice in the fail condition in src/modules/bluetooth/module-bluez5-device.c and src/modules/bluetooth/module-bluez5-device.c. Fixed in 1:8.0-0ubuntu3.14.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Pulseaudio Pulseaudio_project 1:8.0-0ubuntu1 (including) 1:8.0-0ubuntu1 (including)
Pulseaudio Pulseaudio_project 1:8.0-0ubuntu2 (including) 1:8.0-0ubuntu2 (including)
Pulseaudio Pulseaudio_project 1:8.0-0ubuntu3 (including) 1:8.0-0ubuntu3 (including)
Pulseaudio Pulseaudio_project 1:8.0-0ubuntu3.1 (including) 1:8.0-0ubuntu3.1 (including)
Pulseaudio Pulseaudio_project 1:8.0-0ubuntu3.2 (including) 1:8.0-0ubuntu3.2 (including)
Pulseaudio Pulseaudio_project 1:8.0-0ubuntu3.3 (including) 1:8.0-0ubuntu3.3 (including)
Pulseaudio Pulseaudio_project 1:8.0-0ubuntu3.4 (including) 1:8.0-0ubuntu3.4 (including)
Pulseaudio Pulseaudio_project 1:8.0-0ubuntu3.5 (including) 1:8.0-0ubuntu3.5 (including)
Pulseaudio Pulseaudio_project 1:8.0-0ubuntu3.6 (including) 1:8.0-0ubuntu3.6 (including)
Pulseaudio Pulseaudio_project 1:8.0-0ubuntu3.7 (including) 1:8.0-0ubuntu3.7 (including)
Pulseaudio Pulseaudio_project 1:8.0-0ubuntu3.8 (including) 1:8.0-0ubuntu3.8 (including)
Pulseaudio Pulseaudio_project 1:8.0-0ubuntu3.9 (including) 1:8.0-0ubuntu3.9 (including)
Pulseaudio Pulseaudio_project 1:8.0-0ubuntu3.10 (including) 1:8.0-0ubuntu3.10 (including)
Pulseaudio Pulseaudio_project 1:8.0-0ubuntu3.11 (including) 1:8.0-0ubuntu3.11 (including)
Pulseaudio Pulseaudio_project 1:8.0-0ubuntu3.12 (including) 1:8.0-0ubuntu3.12 (including)
Pulseaudio Pulseaudio_project 1:8.0-0ubuntu4 (including) 1:8.0-0ubuntu4 (including)
Pulseaudio Ubuntu trusty *
Pulseaudio Ubuntu xenial *

Potential Mitigations

References