USN-4355-1
Dashboard / Vulnerabilities / USN-4355-1
USN-4355-1
Published: 12 May 2020Last Modified: 22 Apr 2026
Upstream:
Aliases:
Summary: pulseaudio vulnerability
Details: PulseAudio in Ubuntu contains additional functionality to mediate audio recording for snap packages and it was discovered that this functionality did not mediate PulseAudio module unloading. An attacker-controlled snap with only the audio-playback interface connected could exploit this to bypass access controls and record audio.
References: https://ubuntu.com/security/notices/USN-4355-1, https://ubuntu.com/security/CVE-2020-11931, https://launchpad.net/bugs/1877102
Affected packages
Package
Name: pulseaudio
Purl: pkg:deb/ubuntu/pulseaudio@1:8.0-0ubuntu3.12?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -1:8.0-0ubuntu3.12
Affected versions
1:6.0-0ubuntu13
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
