7.2

CVE-2009-1185

Exploit

udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Udev ProjectUdev Version < 141
SuseLinux Enterprise Debuginfo Version10 Updatesp2
SuseLinux Enterprise Debuginfo Version11 Update-
OpensuseOpensuse Version10.3
OpensuseOpensuse Version11.0
OpensuseOpensuse Version11.1
SuseLinux Enterprise Desktop Version10 Updatesp2
SuseLinux Enterprise Desktop Version11 Update-
SuseLinux Enterprise Server Version10 Updatesp2
SuseLinux Enterprise Server Version11 Update-
DebianDebian Linux Version4.0
DebianDebian Linux Version5.0
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version7.10
CanonicalUbuntu Linux Version8.04 SwEdition-
CanonicalUbuntu Linux Version8.10
FedoraprojectFedora Version9
FedoraprojectFedora Version10
JuniperCtpview Version < 7.1
JuniperCtpview Version7.1 Update-
JuniperCtpview Version7.1 Updater1
JuniperCtpview Version7.2 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 89.27% 0.995
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

http://www.securityfocus.com/bid/34536
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1022067
Third Party Advisory
Broken Link
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=495051
Patch
Third Party Advisory
Issue Tracking
https://launchpad.net/bugs/cve/2009-1185
Third Party Advisory
Issue Tracking
https://www.exploit-db.com/exploits/8572
Third Party Advisory
Exploit
VDB Entry