Tavis Ormandy and Julien Tinnes, Google Security Team, discovered a flaw in the way pulseaudio tries to re-exec itself with LD_BIND_NOW environment variable set to 1 that can be exploited by local user to gain root privilegies.
All users of pulseaudio are strongly advised to update to these packages.
Please login to add feedback.
This update has been pushed to stable