MDVSA-2009:103-1 -- Mandriva udev
|ID: oval:org.secpod.oval:def:301207||Date: (C)2012-01-07 (M)2018-02-25|
|Class: PATCH||Family: unix|
Security vulnerabilities have been identified and fixed in udev. udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space . Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service via vectors that trigger a call with crafted arguments . The updated packages have been patched to prevent this. Update: Packages for 2008.0 are being provided due to extended support for Corporate products.
|Mandriva Linux 2008.0|