Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-1159

Опубликовано: 05 окт. 2011
Источник: nvd
CVSS2: 2.1
EPSS Низкий

Описание

acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a crafted application that performs a connect system call but no read system calls.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:tedfelix:acpid:*:*:*:*:*:*:*:*
Версия до 2.0.8 (включая)
cpe:2.3:a:tedfelix:acpid:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid:1.0.10:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid:2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:tedfelix:acpid:2.06:*:*:*:*:*:*:*

EPSS

Процентиль: 39%
0.0017
Низкий

2.1 Low

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
около 14 лет назад

acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a crafted application that performs a connect system call but no read system calls.

redhat
почти 15 лет назад

acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a crafted application that performs a connect system call but no read system calls.

debian
около 14 лет назад

acpid.c in acpid before 2.0.9 does not properly handle a situation in ...

github
больше 3 лет назад

acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a crafted application that performs a connect system call but no read system calls.

fstec
около 14 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие локальному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 39%
0.0017
Низкий

2.1 Low

CVSS2

Дефекты

CWE-20