CVE-2009-1186

Published Apr 17, 2009

Last updated 3 days ago

Overview

Description
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
Source
secalert@redhat.com
NVD status
Modified
Products
udev, linux_enterprise_debuginfo, opensuse, linux_enterprise_desktop, linux_enterprise_server, debian_linux, ubuntu_linux, fedora

Risk scores

CVSS 2.0

Type
Primary
Base score
2.1
Impact score
2.9
Exploitability score
3.9
Vector string
AV:L/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

nvd@nist.gov
CWE-120

Social media

Hype score
Not currently trending

Vendor comments

  • Red HatNot vulnerable. This issue did not affect the versions of udev as shipped with Red Hat Enterprise Linux 4, or 5.

Configurations

References

Sources include official advisories and independent security research.