CVE-2011-2777

Publication date 8 December 2011

Last updated 24 July 2024


Ubuntu priority

samples/powerbtn/powerbtn.sh in acpid (aka acpid2) 2.0.16 and earlier uses the pidof program incorrectly, which allows local users to gain privileges by running a program with the name kded4 and a DBUS_SESSION_BUS_ADDRESS environment variable containing commands.

Status

Package Ubuntu Release Status
acpid 11.10 oneiric
Fixed 1:2.0.10-1ubuntu2.3
11.04 natty
Fixed 1:2.0.7-1ubuntu2.4
10.10 maverick
Fixed 1.0.10-5ubuntu4.4
10.04 LTS lucid
Fixed 1.0.10-5ubuntu2.5
8.04 LTS hardy Ignored end of life

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
acpid

References

Related Ubuntu Security Notices (USN)

    • USN-1296-1
    • acpid vulnerabilities
    • 8 December 2011

Other references