CVE-2009-1185
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2009-1185 from the MITRE CVE dictionary dictionary and NIST NVD.
Statement
This issue has been fixed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2009-0427.html . udev packages as shipped in Red Hat Enterprise Linux 4 were not affected by this flaw, as they do not use netlink sockets for communication. udev is not shipped in Red Hat Enterprise Linux 2.1 and 3.
CVSS v2 metrics
| Base Score | 7.2 |
|---|---|
| Base Metrics | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| Access Vector | Local |
| Access Complexity | Low |
| Authentication | None |
| Confidentiality Impact | Complete |
| Integrity Impact | Complete |
| Availability Impact | Complete |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Red Hat Security Errata
| Platform | Errata | Release Date |
|---|---|---|
| Red Hat Enterprise Linux 5 (udev) | RHSA-2009:0427 | 2009-04-16 |
Acknowledgements
Red Hat would like to thank Sebastian Krahmer of the SUSE Security Team for responsibly reporting this flaw.CVE description copyright © 2017, The MITRE Corporation
