vendor:
Gentoo Linux
by:
Jon Oberheide
7,2
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Gentoo Linux
Affected Version From: < 1.4.1
Affected Version To: < 1.4.1
Patch Exists: YES
Related CWE: CVE-2009-1185
CPE: a:gentoo:gentoo_linux
Metasploit:
https://www.rapid7.com/db/vulnerabilities/vmsa-2009-0009-service-console-package-udev-cve-2009-1185/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2009-1185/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2009-1185/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-0427/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2009-1185/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Gentoo, Intrepid, and Jaunty
2009
udev < 141 Local Privilege Escalation Exploit
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
Mitigation:
Upgrade to udev version 1.4.1 or later.