|
|
| |
|
| |
acpid: multiple vulnerabilities
| Package(s): | acpid |
CVE #(s): | CVE-2011-2777
CVE-2011-4578
|
| Created: | December 9, 2011 |
Updated: | August 17, 2012 |
| Description: |
From the Ubuntu advisory:
Oliver-Tobias Ripka discovered that an ACPI script incorrectly handled power
button events. A local attacker could use this to execute arbitrary code, and
possibly escalate privileges. (CVE-2011-2777)
Helmut Grohne and Michael Biebl discovered that ACPI scripts were executed with
a permissive file mode creation mask (umask). A local attacker could read files
and modify directories created by ACPI scripts that did not set a strict umask.
(CVE-2011-4578) |
| Alerts: |
|
( Log in to post comments)
|
|
|