LWN.net Logo

acpid: multiple vulnerabilities

Package(s):acpid CVE #(s):CVE-2011-2777 CVE-2011-4578
Created:December 9, 2011 Updated:August 17, 2012
Description:

From the Ubuntu advisory:

Oliver-Tobias Ripka discovered that an ACPI script incorrectly handled power button events. A local attacker could use this to execute arbitrary code, and possibly escalate privileges. (CVE-2011-2777)

Helmut Grohne and Michael Biebl discovered that ACPI scripts were executed with a permissive file mode creation mask (umask). A local attacker could read files and modify directories created by ACPI scripts that did not set a strict umask. (CVE-2011-4578)

Alerts:
Debian DSA-2362-1 2011-12-10
Ubuntu USN-1296-1 2011-12-08
Mageia MGASA-2012-0215 2012-08-12
Mageia MGASA-2012-0216 2012-08-12
Mandriva MDVSA-2012:137 2012-08-17
Mandriva MDVSA-2012:138 2012-08-17

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds