A vulnerability in acpid2 may allow a local attacker to gain escalated privileges.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201310-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: acpid2: Privilege escalation Date: October 28, 2013 Bugs: #434522 ID: 201310-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in acpid2 may allow a local attacker to gain escalated privileges. Background ========= acpid2 is a daemon for Advanced Configuration and Power Interface. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-power/acpid < 2.0.17 > = 2.0.17 Description ========== acpid2 does not properly use the pidof program in powerbtn.sh. Impact ===== A local attacker could gain escalated privileges. Workaround ========= There is no known workaround at this time. Resolution ========= All acpid2 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-power/acpid-2.0.17" References ========= [ 1 ] CVE-2011-2777 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2777 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201310-20 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.