CVE-2005-3631
published 2005-12-22CVE-2005-3631: udev does not properly set permissions on certain files in /dev/input, which allows local users to obtain sensitive data that is entered at the console, such…
PriorityP410medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.39%
31.4th percentile
udev does not properly set permissions on certain files in /dev/input, which allows local users to obtain sensitive data that is entered at the console, such as user passwords.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2005-12-20·CVSS 4.6
CVE-2005-3631 [MEDIUM] security flaw
security flaw
udev does not properly set permissions on certain files in /dev/input, which allows local users to obtain sensitive data that is entered at the console, such as user passwords.
GHSA
GHSA-g35h-r364-qwcm: udev does not properly set permissions on certain files in /dev/input, which allows local users to obtain sensitive data that is entered at the consol
ghsa_unreviewed·2022-05-01
CVE-2005-3631 [MEDIUM] GHSA-g35h-r364-qwcm: udev does not properly set permissions on certain files in /dev/input, which allows local users to obtain sensitive data that is entered at the consol
udev does not properly set permissions on certain files in /dev/input, which allows local users to obtain sensitive data that is entered at the console, such as user passwords.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-3631 security flaw
bugzilla·2018-08-16·CVSS 4.6
CVE-2005-3631 [MEDIUM] CVE-2005-3631 security flaw
CVE-2005-3631 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
udev does not properly set permissions on certain files in /dev/input, which allows local users to obtain sensitive data that is entered at the console, such as user passwords.
Bugzilla
udev Permissions Vulnerability (CVE-2005-3631)
bugzilla·2005-12-15·CVSS 4.6
CVE-2005-3631 [MEDIUM] udev Permissions Vulnerability (CVE-2005-3631)
udev Permissions Vulnerability (CVE-2005-3631)
Description of problem:
Josh Bressers wrote:
"Richard Cunningham reported to Red Hat that udev (at least versions 038 and
039, but not some later ones) sets the permissions in /dev/input to 644.
This could allow any logged in user to read from /dev/input/event0, which
will contain things such as keyboard input. I'm attaching the patch from
our maintainer."
This appears to affect FC2.
Discussion:
Removing embargo.
Today Red Hat issued security advisory:
[RHSA-2005:864-01] Important: udev security update
for RHEL 4.
"This update has been rated as having important security impact by the Red
Hat Security Response Team." ...
"The udev package contains an implementation of devfs in userspace using
sysfs and /sbin/hotplug.
"Richard Cunningha
Bugzilla
CVE-2005-3631 /dev/input/* incorrect permissions
bugzilla·2005-12-02·CVSS 4.6
CVE-2005-3631 [MEDIUM] CVE-2005-3631 /dev/input/* incorrect permissions
CVE-2005-3631 /dev/input/* incorrect permissions
/dev/input/* incorrect permissions
This issue was reported to secalert by Richard Cunningham
/dev/input/* has permissions set to 644 by default.
This makes it possible for any user to sniff local user input
(password capturing being the most dangerous).
Discussion:
Harald,
What's your plan for this? I've not communicated this to vendor-sec yet as I
would like to know what an appropriate embargo date should be?
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for
http://secunia.com/advisories/18193http://securitytracker.com/id?1015386http://www.redhat.com/support/errata/RHSA-2005-864.htmlhttp://www.securityfocus.com/bid/15994https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10854http://secunia.com/advisories/18193http://securitytracker.com/id?1015386http://www.redhat.com/support/errata/RHSA-2005-864.htmlhttp://www.securityfocus.com/bid/15994https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10854
2005-12-22
Published