First published: Mon Mar 16 2009(Updated: )
perl-MDK-Common 1.1.11 and 1.1.24, 1.2.9 through 1.2.14, and possibly other versions, in Mandriva Linux does not properly handle strings when writing them to configuration files, which allows attackers to gain privileges via "special characters" in unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mandrakesoft Mandrake Multi Network Firewall | =2.0 | |
Mandrake Linux | =2008.0 | |
Mandrake Linux | =2008.0 | |
Mandrake Linux | =2008.1 | |
Mandrake Linux | =2008.1 | |
Mandrake Linux | =2009.0 | |
Mandrake Linux | =2009.0 | |
Mandriva Linux Corporate Server | =3.0 | |
Mandriva Linux Corporate Server | =3.0 | |
Mandriva Linux Corporate Server | =4.0 | |
Mandriva Linux Corporate Server | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0912 is considered important as it allows attackers to gain elevated privileges on affected Mandriva Linux systems.
To fix CVE-2009-0912, users should upgrade to the patched versions of perl-MDK-Common as provided in Mandriva's security advisories.
CVE-2009-0912 affects perl-MDK-Common versions 1.1.11, 1.1.24, and 1.2.9 through 1.2.14, along with potentially other versions.
CVE-2009-0912 impacts Mandriva Linux and Mandriva Linux Corporate Server installations.
Yes, CVE-2009-0912 can lead to unauthorized access as it allows attackers to exploit improperly handled strings in configuration files.