CVE-2010-1149

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
12/04/2010
Last modified:
11/04/2025

Description

probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discover encryption keys by (1) running a certain udevadm command or (2) reading a certain file under /dev/.udev/db/.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:freedesktop:udisks:*:*:*:*:*:*:*:* 1.0 (including)