Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-4235

Опубликовано: 07 дек. 2009
Источник: redhat
CVSS2: 6.9
EPSS Низкий

Описание

acpid 1.0.4 sets an unrestrictive umask, which might allow local users to leverage weak permissions on /var/log/acpid, and obtain sensitive information by reading this file or cause a denial of service by overwriting this file, a different vulnerability than CVE-2009-4033.

Отчет

Red Hat considers this to be a duplicate of the CVE-2009-4033, rather than a separate issue. For further details, see: https://bugzilla.redhat.com/show_bug.cgi?id=542926#c10

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=542926acpid: log file created with random permissions

EPSS

Процентиль: 11%
0.00037
Низкий

6.9 Medium

CVSS2

Связанные уязвимости

ubuntu
около 16 лет назад

acpid 1.0.4 sets an unrestrictive umask, which might allow local users to leverage weak permissions on /var/log/acpid, and obtain sensitive information by reading this file or cause a denial of service by overwriting this file, a different vulnerability than CVE-2009-4033.

nvd
около 16 лет назад

acpid 1.0.4 sets an unrestrictive umask, which might allow local users to leverage weak permissions on /var/log/acpid, and obtain sensitive information by reading this file or cause a denial of service by overwriting this file, a different vulnerability than CVE-2009-4033.

debian
около 16 лет назад

acpid 1.0.4 sets an unrestrictive umask, which might allow local users ...

github
почти 4 года назад

acpid 1.0.4 sets an unrestrictive umask, which might allow local users to leverage weak permissions on /var/log/acpid, and obtain sensitive information by reading this file or cause a denial of service by overwriting this file, a different vulnerability than CVE-2009-4033.

EPSS

Процентиль: 11%
0.00037
Низкий

6.9 Medium

CVSS2