_______________________________________________________________________
Package : udev
Date : December 3, 2009
Affected: 2008.0
_______________________________________________________________________
Problem Description:
Security vulnerabilities have been identified and fixed in udev.
udev before 1.4.1 does not verify whether a NETLINK message originates
from kernel space, which allows local users to gain privileges by
sending a NETLINK message from user space (CVE-2009-1185).
Buffer overflow in the util_path_encode function in
udev/lib/libudev-util.c in udev before 1.4.1 allows local users to
cause a denial of service (service outage) via vectors that trigger
a call with crafted arguments (CVE-2009-1186).
The updated packages have been patched to prevent this.
Update:
Packages for 2008.0 are being provided due to extended support for
Corporate products.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-1185
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-1186
_______________________________________________________________________