2.1
CVSSv2

CVE-2001-0040

Published: 16/02/2001 Updated: 10/10/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

APC UPS daemon, apcupsd, saves its process ID in a world-writable file, which allows local users to kill an arbitrary process by specifying the target process ID in the apcupsd.pid file.

Vulnerable Product Search on Vulmon Subscribe to Product

apc apcupsd 3.7.2

Exploits

/* Local Denial of Service for any linux box running APCUPSD v372 * * APCUPSD has his pid file world writeable, therefore it is possible * to let it kill another pid and create a denial of service against any * running daemon (when the apcupsd is stopped, for example) * * Bug discovered by: Mattias Dartsch <matze@joonixde> * Explo ...