ACPID Insecure Umask Directory Permissions Vulnerability
BID:11739
Info
ACPID Insecure Umask Directory Permissions Vulnerability
| Bugtraq ID: | 11739 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 17 2004 12:00AM |
| Updated: | Nov 17 2004 12:00AM |
| Credit: | This issue was announced in a SuSE advisory. |
| Vulnerable: |
ACPID ACPID 1.0.3 ACPID ACPID 1.0.1 |
| Not Vulnerable: | |
Discussion
ACPID Insecure Umask Directory Permissions Vulnerability
A vulnerability exists in ACPID that may result in a directory being created with world-writable permissions. This is reportedly due to an insecure umask being set. The vulnerability could reportedly result in a denial of service attacks.
This issue was reported in a SuSE advisory. It is not known if it affects versions of ACPID running on other operating systems or if it is a configuration error specific to the SuSE Linux distribution.
A vulnerability exists in ACPID that may result in a directory being created with world-writable permissions. This is reportedly due to an insecure umask being set. The vulnerability could reportedly result in a denial of service attacks.
This issue was reported in a SuSE advisory. It is not known if it affects versions of ACPID running on other operating systems or if it is a configuration error specific to the SuSE Linux distribution.
Exploit / POC
ACPID Insecure Umask Directory Permissions Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
ACPID Insecure Umask Directory Permissions Vulnerability
Solution:
SuSE has released a security summary report (SUSE-SR:2004:001) to
address these and other issues. The report indicates that fixes for these
issues are available on the SuSE FTP server and also through the YaST
Online Update utility. Customers are advised to peruse the referenced
advisory for further details regarding obtaining and applying appropriate
fixes.
ACPID ACPID 1.0.1
ACPID ACPID 1.0.3
Solution:
SuSE has released a security summary report (SUSE-SR:2004:001) to
address these and other issues. The report indicates that fixes for these
issues are available on the SuSE FTP server and also through the YaST
Online Update utility. Customers are advised to peruse the referenced
advisory for further details regarding obtaining and applying appropriate
fixes.
ACPID ACPID 1.0.1
-
SuSE acpid-1.0.1-259.4.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/acpid-1.0.1-259.4 .i586.patch.rpm -
SuSE acpid-1.0.1-259.4.x86_64.patch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/acpid-1.0.1-2 59.4.x86_64.patch.rpm -
SuSE acpid-1.0.1-265.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/acpid-1.0.1-265.i 586.patch.rpm -
SuSE acpid-1.0.1-265.i586.patch.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/acpid-1.0.1-265.i 586.patch.rpm -
SuSE acpid-1.0.1-265.x86_64.patch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/acpid-1.0.1-2 65.x86_64.patch.rpm -
SuSE acpid-1.0.1-259.4.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.1/rpm/i586/acpid-1.0.1-259.4 .i586.rpm -
SuSE acpid-1.0.1-259.4.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.1/rpm/x86_64/acpid-1.0.1-2 59.4.x86_64.rpm -
SuSE acpid-1.0.1-265.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/acpid-1.0.1-265.i 586.rpm -
SuSE acpid-1.0.1-265.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.0/rpm/i586/acpid-1.0.1-265.i 586.rpm -
SuSE acpid-1.0.1-265.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.0/rpm/x86_64/acpid-1.0.1-2 65.x86_64.rpm
ACPID ACPID 1.0.3
-
SuSE acpid-1.0.3-4.2.x86_64.patch.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/acpid-1.0.3-4 .2.x86_64.patch.rpm -
SuSE acpid-1.0.3-4.2.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/acpid-1.0.3-4 .2.x86_64.rpm