2.1

CVE-2011-1159

Exploit
acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a crafted application that performs a connect system call but no read system calls.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TedfelixAcpid Version <= 2.0.8
TedfelixAcpid Version1.0.8
TedfelixAcpid Version1.0.10
TedfelixAcpid Version2.0.0
TedfelixAcpid Version2.0.1
TedfelixAcpid Version2.0.2
TedfelixAcpid Version2.0.3
TedfelixAcpid Version2.0.4
TedfelixAcpid Version2.0.5
TedfelixAcpid Version2.0.7
TedfelixAcpid Version2.06
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.1% 0.612
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.fedoraproject.org/pipermail/package-announce/2011-May/059880.html
Patch
http://lists.fedoraproject.org/pipermail/package-announce/2011-May/060053.html
Patch
http://secunia.com/advisories/42947
Vendor Advisory
http://secunia.com/advisories/44621
Vendor Advisory
http://www.openwall.com/lists/oss-security/2011/01/19/4
Patch
Exploit
http://www.openwall.com/lists/oss-security/2011/03/15/12
Patch
Exploit
http://www.openwall.com/lists/oss-security/2011/03/15/7
Patch
Exploit
http://www.securityfocus.com/bid/45915
https://bugzilla.redhat.com/show_bug.cgi?id=688698
Patch