|
|
| |
|
| |
udev: multiple vulnerabilities
| Package(s): | udev |
CVE #(s): | CVE-2009-1185
CVE-2009-1186
|
| Created: | April 16, 2009 |
Updated: | December 3, 2009 |
| Description: |
udev has two vulnerabilities, from the Debian alert:
Sebastian Kramer discovered two vulnerabilities in udev, the /dev and
hotplug management daemon.
CVE-2009-1185
udev does not check the origin of NETLINK messages, allowing local
users to gain root privileges.
CVE-2009-1186
udev suffers from a buffer overflow condition in path encoding,
potentially allowing arbitrary code execution. |
| Alerts: |
|
( Log in to post comments)
|
|
|