CVE Vulnerabilities

CVE-2011-2777

Published: Aug 29, 2012 | Modified: Dec 20, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

samples/powerbtn/powerbtn.sh in acpid (aka acpid2) 2.0.16 and earlier uses the pidof program incorrectly, which allows local users to gain privileges by running a program with the name kded4 and a DBUS_SESSION_BUS_ADDRESS environment variable containing commands.

Affected Software

Name Vendor Start Version End Version
Acpid2 Tedfelix * 2.0.16 (including)
Acpid2 Tedfelix 2.0.0 (including) 2.0.0 (including)
Acpid2 Tedfelix 2.0.1 (including) 2.0.1 (including)
Acpid2 Tedfelix 2.0.2 (including) 2.0.2 (including)
Acpid2 Tedfelix 2.0.3 (including) 2.0.3 (including)
Acpid2 Tedfelix 2.0.4 (including) 2.0.4 (including)
Acpid2 Tedfelix 2.0.5 (including) 2.0.5 (including)
Acpid2 Tedfelix 2.0.6 (including) 2.0.6 (including)
Acpid2 Tedfelix 2.0.7 (including) 2.0.7 (including)
Acpid2 Tedfelix 2.0.8 (including) 2.0.8 (including)
Acpid2 Tedfelix 2.0.9 (including) 2.0.9 (including)
Acpid2 Tedfelix 2.0.10 (including) 2.0.10 (including)
Acpid2 Tedfelix 2.0.11 (including) 2.0.11 (including)
Acpid2 Tedfelix 2.0.12 (including) 2.0.12 (including)
Acpid2 Tedfelix 2.0.13 (including) 2.0.13 (including)
Acpid2 Tedfelix 2.0.14 (including) 2.0.14 (including)
Acpid2 Tedfelix 2.0.15 (including) 2.0.15 (including)
Acpid Ubuntu devel *
Acpid Ubuntu hardy *
Acpid Ubuntu lucid *
Acpid Ubuntu maverick *
Acpid Ubuntu natty *
Acpid Ubuntu oneiric *
Acpid Ubuntu upstream *

References