Description
event.c in acpid (aka acpid2) before 2.0.11 does not have an appropriate umask setting during execution of event-handler scripts, which might allow local users to (1) perform write operations within directories created by a script, or (2) read files created by a script, via standard filesystem system calls.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2362-1 | acpid security update |
EUVD |
EUVD-2011-4504 | event.c in acpid (aka acpid2) before 2.0.11 does not have an appropriate umask setting during execution of event-handler scripts, which might allow local users to (1) perform write operations within directories created by a script, or (2) read files created by a script, via standard filesystem system calls. |
Ubuntu USN |
USN-1296-1 | acpid vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T00:09:19.272Z
Reserved: 2011-11-29T00:00:00.000Z
Link: CVE-2011-4578
No data.
Status : Modified
Published: 2012-08-29T22:55:01.237
Modified: 2026-04-29T01:13:23.040
Link: CVE-2011-4578
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN