---
title: "CVE-2008-0008\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2008-0008?format=md
keywords: index, follow
---

# CVE-2008-0008

Publication date 29 January 2008

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The pa\_drop\_root function in PulseAudio 0.9.8, and a certain 0.9.9 build,
does not check return values from (1) setresuid, (2) setreuid, (3) setuid,
and (4) seteuid calls when attempting to drop privileges, which might allow
local users to gain privileges by causing those calls to fail via attacks
such as resource exhaustion.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2008-0008?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| pulseaudio | 7.10 gutsy | Fixed 0.9.6-1ubuntu2.1 |
| 7.04 feisty | Fixed 0.9.5-5ubuntu4.2 |
| 6.10 edgy | Not in release |
| 6.06 LTS dapper | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2008-0008?format=md#patch-details)

## Notes

---

### [jdstrand](https://launchpad.net/~jdstrand)

not possible to exploit in default installation. In fact, need an
LSM to fail the call and then not protect the binary properly, so this is
almost a non-issue on Ubuntu
patched prepared

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| pulseaudio | * Vendor:   <http://www.debian.org/security/2008/dsa-1476> * Vendor:   <http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:027> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0008)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2008-0008)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2008-0008)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2008-0008)

### Related Ubuntu Security Notices (USN)

+ [USN-573-1](https://usn.ubuntu.com/USN-573-1)
+ PulseAudio vulnerability
+ 31 January 2008

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2008-0008>
