2.1
CVSSv2

CVE-2011-1159

Published: 05/10/2011 Updated: 14/05/2012
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

acpid.c in acpid prior to 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a crafted application that performs a connect system call but no read system calls.

Vulnerable Product Search on Vulmon Subscribe to Product

tedfelix acpid 2.0.3

tedfelix acpid 2.0.5

tedfelix acpid 2.06

tedfelix acpid 2.0.7

tedfelix acpid

tedfelix acpid 1.0.8

tedfelix acpid 1.0.10

tedfelix acpid 2.0.0

tedfelix acpid 2.0.1

tedfelix acpid 2.0.2

tedfelix acpid 2.0.4

Vendor Advisories

acpid could be made to stall under certain conditions ...
Multiple vulnerabilities were found in the ACPI Daemon, the Advanced Configuration and Power Interface event daemon: CVE-2011-1159 Vasiliy Kulikov of OpenWall discovered that the socket handling is vulnerable to denial of service CVE-2011-2777 Oliver-Tobias Ripka discovered that incorrect process handling in the Debian-specific po ...

Exploits

source: wwwsecurityfocuscom/bid/45915/info The 'acpid' daemon is prone to multiple local denial-of-service vulnerabilities Successful exploits will allow attackers to cause the application to hang, denying service to legitimate users acpid 1010 is vulnerable; other versions may also be affected #include <stdioh> #include &l ...