Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 508
Alerts This Week
Warning Icon 1 508

Ubuntu 11.10: USN-1296-1 Critical: acpid Local Code Execution

ubuntu
Calendar Grey December 8, 2011
Scroller Ubuntu
Recent patches address vital acpid vulnerabilities impacting various Ubuntu distributions, mitigating risks of possible local code execution.
Several security issues were fixed in acpid.

Summary

Several security issues were fixed in acpid.

Software Description:

- acpid: Advanced Configuration and Power Interface daemon

Details:

Oliver-Tobias Ripka discovered that an ACPI script incorrectly handled power

button events. A local attacker could use this to execute arbitrary code, and

possibly escalate privileges. (CVE-2011-2777)

Helmut Grohne and Michael Biebl discovered that ACPI scripts were executed with

a permissive file mode creation mask (umask). A local attacker could read files

and modify directories created by ACPI scripts that did not set a strict umask.

(CVE-2011-4578)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  acpid                           1:2.0.10-1ubuntu2.3

Ubuntu 11.04:
  acpid                           1:2.0.7-1ubuntu2.4

Ubuntu 10.10:
  acpid                           1.0.10-5ubuntu4.4

Ubuntu 10.04 LTS:
  acpid                           1.0.10-5ubuntu2.5

In general, a standard system update will make all the necessary changes.

References

CVE-2011-2777, CVE-2011-4578

Severity
critical
Lowest
Low
Medium
High
Critical

December 08, 2011

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.