CVE-2011-1828

high

Description

usb-creator-helper in usb-creator before 0.2.28.3 does not enforce intended PolicyKit restrictions, which allows local users to perform arbitrary unmount operations via the UnmountFile method in a dbus-send command.

References

https://launchpad.net/bugs/771553

https://exchange.xforce.ibmcloud.com/vulnerabilities/67241

http://www.vupen.com/english/advisories/2011/1143

http://www.ubuntu.com/usn/usn-1127-1/

http://www.securityfocus.com/bid/47679

http://secunia.com/advisories/44413

Details

Source: Mitre, NVD

Published: 2011-05-16

Updated: 2025-04-11

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00063