7.2
CVSSv2

CVE-2014-0484

Published: 22/09/2014 Updated: 24/09/2014
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Debian acpi-support package prior to 0.140-5+deb7u3 allows local users to gain privileges via vectors related to the "user's environment."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canonical acpi-support 0.140

Vendor Advisories

During a review for EDF, Raphael Geissert discovered that the acpi-support package did not properly handle data obtained from a user's environment This could lead to program malfunction or allow a local user to escalate privileges to the root user due to a programming error For the stable distribution (wheezy), this problem has been fixed in vers ...