vulnerability
Ubuntu: USN-5656-1 (CVE-2019-13351): JACK vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:M/Au:N/C:P/I:P/A:P) | Jul 5, 2019 | Oct 5, 2022 | Nov 15, 2024 |
Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Jul 5, 2019
Added
Oct 5, 2022
Modified
Nov 15, 2024
Description
posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 (as distributed with alsa-plugins 1.1.7 and later) has a "double file descriptor close" issue during a failed connection attempt when jackd2 is not running. Exploitation success depends on multithreaded timing of that double close, which can result in unintended information disclosure, crashes, or file corruption due to having the wrong file associated with the file descriptor.
Solutions
ubuntu-pro-upgrade-jackd2ubuntu-pro-upgrade-jackd2-firewireubuntu-pro-upgrade-libjack-jackd2-0
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.