CVE-2011-4578

event.c in acpid (aka acpid2) before 2.0.11 does not have an appropriate umask setting during execution of event-handler scripts, which might allow local users to (1) perform write operations within directories created by a script, or (2) read files created by a script, via standard filesystem system calls.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tedfelix:acpid2:*:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid2:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid2:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid2:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid2:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid2:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid2:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid2:2.0.6:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid2:2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid2:2.0.8:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid2:2.0.9:*:*:*:*:*:*:*

History

21 Nov 2024, 01:32

Type Values Removed Values Added
References () http://sourceforge.net/u/tedfelix/acpid2/ci/02d0bf29207f17996936ab652717855b15873901/tree/Changelog?force=True - () http://sourceforge.net/u/tedfelix/acpid2/ci/02d0bf29207f17996936ab652717855b15873901/tree/Changelog?force=True -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2012:138 - () http://www.mandriva.com/security/advisories?name=MDVSA-2012:138 -
References () http://www.openwall.com/lists/oss-security/2011/12/06/3 - () http://www.openwall.com/lists/oss-security/2011/12/06/3 -
References () https://bugs.launchpad.net/ubuntu/+source/acpid/+bug/893821 - () https://bugs.launchpad.net/ubuntu/+source/acpid/+bug/893821 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=760984 - () https://bugzilla.redhat.com/show_bug.cgi?id=760984 -

Information

Published : 2012-08-29 22:55

Updated : 2025-04-11 00:51


NVD link : CVE-2011-4578

Mitre link : CVE-2011-4578

CVE.ORG link : CVE-2011-4578


JSON object : View

Products Affected

tedfelix

  • acpid2
CWE
CWE-264

Permissions, Privileges, and Access Controls