CVE-2009-1186Classic Buffer Overflow in Project Udev

Severity
2.1LOWNVD
EPSS
0.1%
top 75.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17
Latest updateMay 2

Description

Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.

CVSS vector

AV:L/AC:L/C:N/I:N/A:PExploitability: 3.9 | Impact: 2.9

Affected Packages5 packages

Also affects: Debian Linux 4.0, 5.0, Fedora 10, 9, Ubuntu Linux 6.06, 7.10, 8.04, 8.10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m6q5-8596-f8v2: Buffer overflow in the util_path_encode function in udev/lib/libudev-util2022-05-02
CVEList
CVE-2009-1186: Buffer overflow in the util_path_encode function in udev/lib/libudev-util2009-04-17

📋Vendor Advisories

2
Red Hat
udev: Buffer overflow in path encoding routine2009-04-15
Ubuntu
udev vulnerabilities2009-04-15

💬Community

1
Bugzilla
CVE-2009-1186 udev: Buffer overflow in path encoding routine2009-04-09
CVE-2009-1186 — Classic Buffer Overflow in Project Udev | cvebase