Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 297381 - sys-power/acpid DOS, information leak (CVE-2009-4235)
Summary: sys-power/acpid DOS, information leak (CVE-2009-4235)
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [ebuild?]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-12-18 01:27 UTC by Stefan Behte (RETIRED)
Modified: 2009-12-18 01:32 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2009-12-18 01:27:21 UTC
CVE-2009-4235 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-4235):
  acpid 1.0.4 sets an unrestrictive umask, which might allow local
  users to leverage weak permissions on /var/log/acpid, and obtain
  sensitive information by reading this file or cause a denial of
  service by overwriting this file, a different vulnerability than
  CVE-2009-4033.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2009-12-18 01:32:54 UTC
upon further investigation, because of CVE-2009-4033, I found this:

http://rhn.redhat.com/errata/RHSA-2009-1642.html:
Comment #4 From  Tomas Hoger  2009-12-01 10:02:52 EDT  -------

Marc Deslauriers pointed out that missing mode argument in /dev/null open call
is not from upstream 1.0.4 source, but rather a change from Red Hat patch
acpid-1.0.4-fd.patch.

So closing invalid.