CVE-2010-1149 describes an information disclosure vulnerability in udisks versions prior to 1.0.1, specifically within the probers/udisks-dm-export.c component. This flaw allows local users to discover encryption keys by improperly exporting UDISKS_DM_TARGETS_PARAMS information to udev, even for encrypted volumes. Attackers can exploit this by running a specific udevadm command or reading a file under /dev/.udev/db/. The vulnerability has a low severity CVSS score of 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N), indicating local access with low attack complexity is required to achieve partial confidentiality impact. There is no impact on integrity or availability. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are negligible, suggesting a low level of public awareness or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0CPE matchmatch criteria | cpe:2.3:a:freedesktop:udisks:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.