CVE Vulnerabilities

CVE-2009-1185

Origin Validation Error

Published: Apr 17, 2009 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
7.2 IMPORTANT
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
HIGH

udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
Udev Udev_project * 141 (excluding)
Red Hat Enterprise Linux 5 RedHat udev-0:095-14.20.el5_3 *
Udev Ubuntu dapper *
Udev Ubuntu gutsy *
Udev Ubuntu hardy *
Udev Ubuntu intrepid *
Udev Ubuntu upstream *

References