Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-4235

Опубликовано: 07 дек. 2009
Источник: redhat
CVSS2: 6.9

Описание

acpid 1.0.4 sets an unrestrictive umask, which might allow local users to leverage weak permissions on /var/log/acpid, and obtain sensitive information by reading this file or cause a denial of service by overwriting this file, a different vulnerability than CVE-2009-4033.

Отчет

Red Hat considers this to be a duplicate of the CVE-2009-4033, rather than a separate issue. For further details, see: https://bugzilla.redhat.com/show_bug.cgi?id=542926#c10

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=542926acpid: log file created with random permissions

6.9 Medium

CVSS2

Связанные уязвимости

ubuntu
около 16 лет назад

acpid 1.0.4 sets an unrestrictive umask, which might allow local users to leverage weak permissions on /var/log/acpid, and obtain sensitive information by reading this file or cause a denial of service by overwriting this file, a different vulnerability than CVE-2009-4033.

nvd
около 16 лет назад

acpid 1.0.4 sets an unrestrictive umask, which might allow local users to leverage weak permissions on /var/log/acpid, and obtain sensitive information by reading this file or cause a denial of service by overwriting this file, a different vulnerability than CVE-2009-4033.

debian
около 16 лет назад

acpid 1.0.4 sets an unrestrictive umask, which might allow local users ...

github
больше 3 лет назад

acpid 1.0.4 sets an unrestrictive umask, which might allow local users to leverage weak permissions on /var/log/acpid, and obtain sensitive information by reading this file or cause a denial of service by overwriting this file, a different vulnerability than CVE-2009-4033.

6.9 Medium

CVSS2