udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
The product does not properly verify that the source of data or communication is valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Udev | Udev_project | * | 141 (excluding) |
Red Hat Enterprise Linux 5 | RedHat | udev-0:095-14.20.el5_3 | * |
Udev | Ubuntu | dapper | * |
Udev | Ubuntu | gutsy | * |
Udev | Ubuntu | hardy | * |
Udev | Ubuntu | intrepid | * |
Udev | Ubuntu | upstream | * |