MidnightBSD

Advisories for tedfelix

CVE-2011-1159 LOW

acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a crafted application that performs a connect system call but no read system calls.

CVSS 2.0

Severity: LOW

Problem Type: CWE-20,

Products Affected

Vendor Product Version
tedfelix acpid 2.06
tedfelix acpid 2.0.3
tedfelix acpid 2.0.2
tedfelix acpid 2.0.5
tedfelix acpid 2.0.7
tedfelix acpid 2.0.4
tedfelix acpid 2.0.0
tedfelix acpid 2.0.1
tedfelix acpid *
tedfelix acpid 1.0.8
tedfelix acpid 1.0.10
CVE-2011-2777 MEDIUM

samples/powerbtn/powerbtn.sh in acpid (aka acpid2) 2.0.16 and earlier uses the pidof program incorrectly, which allows local users to gain privileges by running a program with the name kded4 and a DBUS_SESSION_BUS_ADDRESS environment variable containing commands.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
tedfelix acpid2 2.0.13
tedfelix acpid2 2.0.0
tedfelix acpid2 2.0.10
tedfelix acpid2 2.0.2
tedfelix acpid2 2.0.9
tedfelix acpid2 2.0.7
tedfelix acpid2 2.0.1
tedfelix acpid2 2.0.6
tedfelix acpid2 2.0.3
tedfelix acpid2 *
tedfelix acpid2 2.0.4
tedfelix acpid2 2.0.12
tedfelix acpid2 2.0.5
tedfelix acpid2 2.0.8
tedfelix acpid2 2.0.11
tedfelix acpid2 2.0.15
tedfelix acpid2 2.0.14
CVE-2011-4578 MEDIUM

event.c in acpid (aka acpid2) before 2.0.11 does not have an appropriate umask setting during execution of event-handler scripts, which might allow local users to (1) perform write operations within directories created by a script, or (2) read files created by a script, via standard filesystem system calls.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
tedfelix acpid2 2.0.0
tedfelix acpid2 *
tedfelix acpid2 2.0.3
tedfelix acpid2 2.0.4
tedfelix acpid2 2.0.2
tedfelix acpid2 2.0.5
tedfelix acpid2 2.0.9
tedfelix acpid2 2.0.8
tedfelix acpid2 2.0.7
tedfelix acpid2 2.0.6
tedfelix acpid2 2.0.1