MDVSA-2009:103-1 -- Mandriva udevID: oval:org.secpod.oval:def:301207 | Date: (C)2012-01-07 (M)2023-02-20 |
Class: PATCH | Family: unix |
Security vulnerabilities have been identified and fixed in udev. udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space . Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service via vectors that trigger a call with crafted arguments . The updated packages have been patched to prevent this. Update: Packages for 2008.0 are being provided due to extended support for Corporate products.
Platform: |
Mandriva Linux 2008.0 |