CVE-2011-0640: Medium severity uwamp vulnerability
The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attackers to execute arbitrary programs via crafted USB data, as demonstrated by keyboard and mouse data sent by malware on a smartphone that the user connected to the computer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0640?
CVE-2011-0640 has been classified as a moderate-severity vulnerability.
How do I fix CVE-2011-0640?
To mitigate CVE-2011-0640, users should reconfigure udev to disable automatic enabling of additional USB HID functionality.
What systems are affected by CVE-2011-0640?
CVE-2011-0640 affects systems running the default configuration of udev on Linux.
What type of attack does CVE-2011-0640 enable?
CVE-2011-0640 enables user-assisted attackers to execute arbitrary programs via crafted USB data.
Is there a workaround for CVE-2011-0640?
A potential workaround for CVE-2011-0640 includes implementing policies to restrict the usage of untrusted USB devices.