FEDORA-2011-6681Vendor advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-May/059880.html CVE-2011-1159
acpid 1.0.x - Multiple Local Denial of Service Vulnerabilities
Record summary
CVE-2011-1159 has a selected CVSS score of 2.1; EIP currently links 1 catalogued exploit.
Description
acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a crafted application that performs a connect system call but no read system calls.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBacpid 1.0.x - Multiple Local Denial of Service VulnerabilitiesExploitDB exploitby Vasiliy KulikovNot analyzed1 file
References
10FEDORA-2011-6460Vendor advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-May/060053.html 42947Third-party advisory
http://secunia.com/advisories/42947 44621Third-party advisory
http://secunia.com/advisories/44621 [oss-security] 20110119 2 acpid flawsmailing list
http://www.openwall.com/lists/oss-security/2011/01/19/4 [oss-security] 20110315 Re: 2 acpid flawsmailing list
http://www.openwall.com/lists/oss-security/2011/03/15/12 [oss-security] 20110315 Re: 2 acpid flawsmailing list
http://www.openwall.com/lists/oss-security/2011/03/15/7 45915vdb entry
http://www.securityfocus.com/bid/45915 bugzilla.redhat.comConfirmation
https://bugzilla.redhat.com/show_bug.cgi?id=688698 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2011-1159