probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discover encryption keys by (1) running a certain udevadm command or (2) reading a certain file under /dev/.udev/db/.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2010-04-12T18:00:00Z

Updated: 2024-08-07T01:14:06.397Z

Reserved: 2010-03-29T00:00:00Z

Link: CVE-2010-1149

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2010-04-12T18:30:00.790

Modified: 2010-04-13T04:00:00.000

Link: CVE-2010-1149

cve-icon Redhat

Severity : Moderate

Publid Date: 2010-04-06T00:00:00Z

Links: CVE-2010-1149 - Bugzilla