MEDIUM · 4.4

CVE-2011-2777

samples/powerbtn/powerbtn.sh in acpid (aka acpid2) 2.0.16 and earlier uses the pidof program incorrectly, which allows local users to gain privileges by running a program with the name kded4 and a DBU...

Vulnerability Description

samples/powerbtn/powerbtn.sh in acpid (aka acpid2) 2.0.16 and earlier uses the pidof program incorrectly, which allows local users to gain privileges by running a program with the name kded4 and a DBUS_SESSION_BUS_ADDRESS environment variable containing commands.

CVSS Score

4.4

MEDIUM

AV:L/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
TedfelixAcpid2<= 2.0.16

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-2777?

CVE-2011-2777 is a vulnerability with a CVSS score of 4.4 (MEDIUM). samples/powerbtn/powerbtn.sh in acpid (aka acpid2) 2.0.16 and earlier uses the pidof program incorrectly, which allows local users to gain privileges by running a program with the name kded4 and a DBU...

How severe is CVE-2011-2777?

CVE-2011-2777 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-2777?

Check the references section above for vendor advisories and patch information. Affected products include: Tedfelix Acpid2.