Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 393487 (CVE-2011-4578) - <sys-power/acpid-2.0.11 unrespected umask for scripts run by acpid (CVE-2011-4578)
Summary: <sys-power/acpid-2.0.11 unrespected umask for scripts run by acpid (CVE-2011-...
Status: RESOLVED FIXED
Alias: CVE-2011-4578
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://www.openwall.com/lists/oss-sec...
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-12-07 09:09 UTC by Agostino Sarubbo
Modified: 2012-09-08 15:28 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2011-12-07 09:09:24 UTC
From oss-security mailing list at $URL:


------
* Sat Jul 30 2011  Ted Felix <http://www.tedfelix.com>
  - 2.0.11 release
  - Set umask to 0077 for scripts run by acpid.  (event.c)  (Ted Felix)
------

Discovered by Helmut Grohne and Michael Biebl.


Already fix in tree, just to track CVE.
Comment 1 Agostino Sarubbo gentoo-dev 2011-12-07 15:03:59 UTC
Secunia advisory reference:

https://secunia.com/advisories/47071/
Comment 2 Tim Sammut (RETIRED) gentoo-dev 2011-12-07 16:52:57 UTC
Thanks, Agostino. GLSA Vote: no.
Comment 3 Sean Amoss (RETIRED) gentoo-dev Security 2012-03-06 21:19:26 UTC
Vote: no.

Closing noglsa.
Comment 4 GLSAMaker/CVETool Bot gentoo-dev 2012-09-08 15:28:12 UTC
CVE-2011-4578 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4578):
  event.c in acpid (aka acpid2) before 2.0.11 does not have an appropriate
  umask setting during execution of event-handler scripts, which might allow
  local users to (1) perform write operations within directories created by a
  script, or (2) read files created by a script, via standard filesystem
  system calls.