4.4

CVE-2011-2777

samples/powerbtn/powerbtn.sh in acpid (aka acpid2) 2.0.16 and earlier uses the pidof program incorrectly, which allows local users to gain privileges by running a program with the name kded4 and a DBUS_SESSION_BUS_ADDRESS environment variable containing commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tedfelix ≫ Acpid2 Version <= 2.0.16
Tedfelix ≫ Acpid2 Version 2.0.0
Tedfelix ≫ Acpid2 Version 2.0.1
Tedfelix ≫ Acpid2 Version 2.0.2
Tedfelix ≫ Acpid2 Version 2.0.3
Tedfelix ≫ Acpid2 Version 2.0.4
Tedfelix ≫ Acpid2 Version 2.0.5
Tedfelix ≫ Acpid2 Version 2.0.6
Tedfelix ≫ Acpid2 Version 2.0.7
Tedfelix ≫ Acpid2 Version 2.0.8
Tedfelix ≫ Acpid2 Version 2.0.9
Tedfelix ≫ Acpid2 Version 2.0.10
Tedfelix ≫ Acpid2 Version 2.0.11
Tedfelix ≫ Acpid2 Version 2.0.12
Tedfelix ≫ Acpid2 Version 2.0.13
Tedfelix ≫ Acpid2 Version 2.0.14
Tedfelix ≫ Acpid2 Version 2.0.15
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.61% 0.446
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://bugs.launchpad.net/ubuntu/+source/acpid/+bug/893821