LWN.net Logo

udev: multiple vulnerabilities

Package(s):udev CVE #(s):CVE-2009-1185 CVE-2009-1186
Created:April 16, 2009 Updated:December 3, 2009
Description: udev has two vulnerabilities, from the Debian alert:

Sebastian Kramer discovered two vulnerabilities in udev, the /dev and hotplug management daemon.

CVE-2009-1185 udev does not check the origin of NETLINK messages, allowing local users to gain root privileges.

CVE-2009-1186 udev suffers from a buffer overflow condition in path encoding, potentially allowing arbitrary code execution.

Alerts:
Mandriva MDVSA-2009:103-1 2009-12-03
Mandriva MDVSA-2009:104 2009-04-30
Mandriva MDVSA-2009:103 2009-04-30
Slackware SSA:2009-111-01 2009-04-21
SuSE SUSE-SA:2009:020 2009-04-16
SuSE SUSE-SA:2009:025 2009-04-22
Slackware SSA:2009-111-02 2009-04-22
Gentoo 200904-18 2009-04-18
CentOS CESA-2009:0427 2009-04-20
rPath rPSA-2009-0063-1 2009-04-17
Fedora FEDORA-2009-3711 2009-04-16
Fedora FEDORA-2009-3712 2009-04-16
Ubuntu USN-758-1 2009-04-15
Debian DSA-1772-1 2009-04-16
Red Hat RHSA-2009:0427-01 2009-04-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds