MEDIUM · 4.6

CVE-2011-4578

event.c in acpid (aka acpid2) before 2.0.11 does not have an appropriate umask setting during execution of event-handler scripts, which might allow local users to (1) perform write operations within d...

Vulnerability Description

event.c in acpid (aka acpid2) before 2.0.11 does not have an appropriate umask setting during execution of event-handler scripts, which might allow local users to (1) perform write operations within directories created by a script, or (2) read files created by a script, via standard filesystem system calls.

CVSS Score

4.6

MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
TedfelixAcpid2<= 2.0.10

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-4578?

CVE-2011-4578 is a vulnerability with a CVSS score of 4.6 (MEDIUM). event.c in acpid (aka acpid2) before 2.0.11 does not have an appropriate umask setting during execution of event-handler scripts, which might allow local users to (1) perform write operations within d...

How severe is CVE-2011-4578?

CVE-2011-4578 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-4578?

Check the references section above for vendor advisories and patch information. Affected products include: Tedfelix Acpid2.