<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="d740755926641b68adc21863744e2258"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="768">
  <id>dbg111-libudev-devel</id>
  <title>udev: Fixed local privilege escalation</title>
  <release>openSUSE 11.1</release>
  <issued date="1239704169"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=493158" id="493158" title="bug number 493158" type="bugzilla"/>
  </references>
  <description>This update fixes a local privilege escalation in udev.

CVE-2009-1185: udev did not check the origin of the netlink
messages. A local attacker could fake device create events
and so gain root privileges.
</description>
  <pkglist>
    <collection>
        <package name="udev-debuginfo" arch="i586" version="128" release="9.7.1">
          <filename>udev-debuginfo-128-9.7.1.i586.rpm</filename>
        </package>
        <package name="udev-debuginfo" arch="ppc" version="128" release="9.7.1">
          <filename>udev-debuginfo-128-9.7.1.ppc.rpm</filename>
        </package>
        <package name="udev-debuginfo" arch="x86_64" version="128" release="9.7.1">
          <filename>udev-debuginfo-128-9.7.1.x86_64.rpm</filename>
        </package>
        <package name="udev-debugsource" arch="i586" version="128" release="9.7.1">
          <filename>udev-debugsource-128-9.7.1.i586.rpm</filename>
        </package>
        <package name="udev-debugsource" arch="ppc" version="128" release="9.7.1">
          <filename>udev-debugsource-128-9.7.1.ppc.rpm</filename>
        </package>
        <package name="udev-debugsource" arch="x86_64" version="128" release="9.7.1">
          <filename>udev-debugsource-128-9.7.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
