PT-2009-6722 · Linux+2 · Libvolume-Id0+10

Jan Lieskovsky

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2009-1186

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions udev versions prior to 1.4.1 libudev0-128 libudev-devel-128 libvolume-id0 libvolume id-devel-128 libvolume id1-128 udev-udeb udev-debugsource-128 udev-128 udev-debuginfo-128 udev-debuginfo-085 libvolume-id-dev
Description The issue concerns multiple vulnerabilities in the udev package of various Linux distributions, including SUSE Linux Enterprise and Debian GNU/Linux. These vulnerabilities can be exploited locally, potentially leading to a breach of confidentiality, integrity, and availability of protected information. A buffer overflow in the util path encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service via crafted arguments.
Recommendations For udev versions prior to 1.4.1, update to version 1.4.1 or later to resolve the issue. For libudev0-128, libudev-devel-128, libvolume-id0, libvolume id-devel-128, libvolume id1-128, udev-udeb, udev-debugsource-128, udev-128, udev-debuginfo-128, and udev-debuginfo-085, consider disabling the vulnerable components until a patch is available. As a temporary workaround, restrict access to the vulnerable modules to minimize the risk of exploitation. Avoid using crafted arguments that may trigger the buffer overflow in the util path encode function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability in some of the affected packages.

Exploit

Fix

Origin Validation Error

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03658
BDU:2015-03659
BDU:2015-03660
BDU:2015-03661
BDU:2015-04379
BDU:2015-04380
BDU:2015-04381
BDU:2015-04382
BDU:2015-04383
BDU:2015-04384
BDU:2015-04385
BDU:2015-04386
CVE-2009-1186
DSA-1772-1

Affected Products

Debian
Suse Linux Enterprise
Libudev-Devel
Libudev0
Libvolume Id-Devel
Libvolume-Id0
Libvolume Id1
Udev
Udev-Debuginfo
Udev-Debugsource
Udev-Udeb