Lucene search

K
ubuntuUbuntuUSN-2297-1
HistoryJul 22, 2014 - 12:00 a.m.

acpi-support vulnerability

2014-07-2200:00:00
ubuntu.com
39

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.1

Confidence

Low

EPSS

0

Percentile

5.1%

Releases

  • Ubuntu 12.04

Packages

  • acpi-support - scripts for handling many ACPI events

Details

CESG discovered that acpi-support incorrectly handled certain privileged
operations when checking for power management daemons. A local attacker
could use this flaw to execute arbitrary code and elevate privileges to
root.

OSVersionArchitecturePackageVersionFilename
Ubuntu12.04noarchacpi-support< 0.140.2UNKNOWN

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.1

Confidence

Low

EPSS

0

Percentile

5.1%