RedHat Enterprise Linux UDEV Insecure Permissions Vulnerability
BID:15994
Info
RedHat Enterprise Linux UDEV Insecure Permissions Vulnerability
| Bugtraq ID: | 15994 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-3631 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 20 2005 12:00AM |
| Updated: | Mar 03 2006 05:06AM |
| Credit: | Richard Cunningham reported this issue to the vendor. |
| Vulnerable: |
Redhat Fedora Core3 Redhat Fedora Core2 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 |
| Not Vulnerable: | |
Discussion
RedHat Enterprise Linux UDEV Insecure Permissions Vulnerability
Red Hat Enterprise Linux is susceptible to an insecure-permissions vulnerability. This issue is due to a flaw in the 'udev' package that improperly creates '/dev/input' files.
This issue allows local attackers to improperly access files in '/dev/input'. This allows them to sniff user-supplied keyboard and mouse input. Information gathered through this issue, such as passwords, will aid malicious users in further attacks.
Red Hat Enterprise Linux is susceptible to an insecure-permissions vulnerability. This issue is due to a flaw in the 'udev' package that improperly creates '/dev/input' files.
This issue allows local attackers to improperly access files in '/dev/input'. This allows them to sniff user-supplied keyboard and mouse input. Information gathered through this issue, such as passwords, will aid malicious users in further attacks.
Exploit / POC
RedHat Enterprise Linux UDEV Insecure Permissions Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
RedHat Enterprise Linux UDEV Insecure Permissions Vulnerability
Solution:
Red Hat has released advisory RHSA-2005:864-6, along with fixes to address this issue.
Please see the referenced vendor advisories for further information on obtaining fixes.
Solution:
Red Hat has released advisory RHSA-2005:864-6, along with fixes to address this issue.
Please see the referenced vendor advisories for further information on obtaining fixes.
References
RedHat Enterprise Linux UDEV Insecure Permissions Vulnerability
References:
References: