CVE-2011-4578

Publication date 6 December 2011

Last updated 24 July 2024


Ubuntu priority

event.c in acpid (aka acpid2) before 2.0.11 does not have an appropriate umask setting during execution of event-handler scripts, which might allow local users to (1) perform write operations within directories created by a script, or (2) read files created by a script, via standard filesystem system calls.

Status

Package Ubuntu Release Status
acpid 11.10 oneiric
Fixed 1:2.0.10-1ubuntu2.3
11.04 natty
Fixed 1:2.0.7-1ubuntu2.4
10.10 maverick
Fixed 1.0.10-5ubuntu4.4
10.04 LTS lucid
Fixed 1.0.10-5ubuntu2.5
8.04 LTS hardy Ignored end of life

References

Related Ubuntu Security Notices (USN)

    • USN-1296-1
    • acpid vulnerabilities
    • 8 December 2011

Other references