CVE-2011-0640

The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attackers to execute arbitrary programs via crafted USB data, as demonstrated by keyboard and mouse data sent by malware on a smartphone that the user connected to the computer.
Configurations

Configuration 1 (hide)

cpe:2.3:a:udev_project:udev:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2011-01-25 01:00

Updated : 2024-02-28 11:41


NVD link : CVE-2011-0640

Mitre link : CVE-2011-0640

CVE.ORG link : CVE-2011-0640


JSON object : View

Products Affected

udev_project

  • udev