udev does not properly set permissions on certain files in /dev/input, which allows local users to obtain sensitive data that is entered at the console, such as user passwords.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://securitytracker.com/id?1015386 | vdb entry |
http://www.securityfocus.com/bid/15994 | patch vdb entry |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10854 | signature vdb entry |
http://www.redhat.com/support/errata/RHSA-2005-864.html | patch vendor advisory |
http://secunia.com/advisories/18193 | patch vendor advisory third party advisory |