CVE-2009-1186
published 2009-04-17CVE-2009-1186: Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service…
PriorityP48low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.54%
41.6th percentile
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_debuginfo | — | — |
| suse | linux_enterprise_debuginfo | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| udev_project | udev | < 141 | 141 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
vendor_ubuntu7.2HIGH
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m6q5-8596-f8v2: Buffer overflow in the util_path_encode function in udev/lib/libudev-util
ghsa_unreviewed·2022-05-02
CVE-2009-1186 [LOW] CWE-119 GHSA-m6q5-8596-f8v2: Buffer overflow in the util_path_encode function in udev/lib/libudev-util
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
Red Hat
udev: Buffer overflow in path encoding routine
vendor_redhat·2009-04-15·CVSS 2.1
CVE-2009-1186 [LOW] udev: Buffer overflow in path encoding routine
udev: Buffer overflow in path encoding routine
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
Statement: Not vulnerable. This issue did not affect the versions of udev as shipped with Red Hat Enterprise Linux 4, or 5.
Ubuntu
udev vulnerabilities
vendor_ubuntu·2009-04-15·CVSS 7.2
CVE-2009-1185 [HIGH] udev vulnerabilities
Title: udev vulnerabilities
Summary: udev vulnerabilities
Sebastian Krahmer discovered that udev did not correctly validate netlink
message senders. A local attacker could send specially crafted messages
to udev in order to gain root privileges. (CVE-2009-1185)
Sebastian Krahmer discovered a buffer overflow in the path encoding routines
in udev. A local attacker could exploit this to crash udev, leading to a
denial of service. (CVE-2009-1186)
Instructions: After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/hotplug/udev.git%3Ba=commitdiff%3Bh=662c3110803bd8c1aedacc36788e6fd028944314http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00006.htmlhttp://secunia.com/advisories/34731http://secunia.com/advisories/34750http://secunia.com/advisories/34753http://secunia.com/advisories/34771http://secunia.com/advisories/34776http://secunia.com/advisories/34785http://secunia.com/advisories/34787http://secunia.com/advisories/34801http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.446399http://wiki.rpath.com/Advisories:rPSA-2009-0063http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0063http://www.debian.org/security/2009/dsa-1772http://www.gentoo.org/security/en/glsa/glsa-200904-18.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:103http://www.securityfocus.com/archive/1/502752/100/0/threadedhttp://www.securityfocus.com/bid/34539http://www.securitytracker.com/id?1022068http://www.ubuntu.com/usn/usn-758-1http://www.vupen.com/english/advisories/2009/1053https://bugzilla.redhat.com/show_bug.cgi?id=495052https://launchpad.net/bugs/cve/2009-1186https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00462.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00463.htmlhttp://git.kernel.org/?p=linux/hotplug/udev.git%3Ba=commitdiff%3Bh=662c3110803bd8c1aedacc36788e6fd028944314http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00006.htmlhttp://secunia.com/advisories/34731http://secunia.com/advisories/34750http://secunia.com/advisories/34753http://secunia.com/advisories/34771http://secunia.com/advisories/34776http://secunia.com/advisories/34785http://secunia.com/advisories/34787http://secunia.com/advisories/34801http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.446399http://wiki.rpath.com/Advisories:rPSA-2009-0063http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0063http://www.debian.org/security/2009/dsa-1772http://www.gentoo.org/security/en/glsa/glsa-200904-18.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:103http://www.securityfocus.com/archive/1/502752/100/0/threadedhttp://www.securityfocus.com/bid/34539http://www.securitytracker.com/id?1022068http://www.ubuntu.com/usn/usn-758-1http://www.vupen.com/english/advisories/2009/1053https://bugzilla.redhat.com/show_bug.cgi?id=495052https://launchpad.net/bugs/cve/2009-1186https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00462.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00463.html
2009-04-17
Published