vendor:
Ubuntu Linux
by:
fuzz
7,2
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: Ubuntu Linux
Affected Version From: Ubuntu 10.04
Affected Version To: Ubuntu 10.10
Patch Exists: YES
Related CWE: CVE-2010-1163
CPE: o:ubuntu:ubuntu_linux:10.04
Metasploit:
https://www.rapid7.com/db/vulnerabilities/freebsd-vid-1a9f678d-48ca-11df-85f8-000c29a67389/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2010-1163/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2010-1163/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2010-1163/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0361/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0476/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2010
UDEV Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to gain elevated privileges on vulnerable installations of UDEV. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UDEV daemon. The issue lies in the fact that the daemon does not properly validate the source of events. An attacker can craft a malicious event and inject it into the UDEV daemon. This can be used to execute arbitrary code with elevated privileges.
Mitigation:
Upgrade to the latest version of UDEV.