[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2009:103 -- Mandriva udev

ID: oval:org.secpod.oval:def:301230Date: (C)2012-01-07   (M)2023-02-20
Class: PATCHFamily: unix




Security vulnerabilities have been identified and fixed in udev. udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space . Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service via vectors that trigger a call with crafted arguments . The updated packages have been patched to prevent this.

Platform:
Mandriva Linux 2009.0
Mandriva Linux 2008.1
Product:
udev
Reference:
MDVSA-2009:103
CVE-2009-1186
CVE-2009-1185
CVE    2
CVE-2009-1186
CVE-2009-1185
CPE    2
cpe:/o:mandriva:linux:2008.1
cpe:/o:mandriva:linux:2009.0

© SecPod Technologies