PT-2011-1036 · Acpid · Acpid

Vincent Danen

·

Publicado

2011-10-05

·

Atualizado

2012-05-14

·

CVE-2011-1159

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions acpid versions prior to 2.0.9
Description The issue allows local users to cause a denial of service, potentially disrupting the confidentiality, integrity, and availability of protected information. This can be achieved through a crafted application that connects to acpid.socket but does not perform any read system calls, causing the daemon to hang. A local attacker can exploit this situation.
Recommendations For versions prior to 2.0.9, update to version 2.0.9 or later to resolve the issue. As a temporary workaround, consider restricting access to acpid.socket to minimize the risk of exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02177
CVE-2011-1159
DSA-2362-1

Produtos afetados

Acpid