« Volver al listado

CVE-2011-1159

Estado: ModificadaBaja (2.1)—

acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a crafted application that performs a connect system call but no read system calls.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-1159",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-10-05T02:56:24.660",
  "references": [
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-May/059880.html",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-May/060053.html",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/42947",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/44621",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2011/01/19/4",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2011/03/15/12",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2011/03/15/7",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/45915",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=688698",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-May/059880.html",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-May/060053.html",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/42947",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/44621",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2011/01/19/4",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2011/03/15/12",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2011/03/15/7",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/45915",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=688698",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a crafted application that performs a connect system call but no read system calls."
    },
    {
      "lang": "es",
      "value": "acpid.c de acpid en versiones anteriores a 2.0.9 no maneja apropiadamente una situación en la que un proceso se ha conectado a un acpid.socket pero no está leyendo ningún dato, lo que permite a usuarios locales provocar una denegación de servicio (cuelgue del demonio) a través de una aplicación modificada que que realiza una llamada al sistema de conexión pero no de lectura."
    }
  ],
  "lastModified": "2026-06-16T23:28:50.630",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tedfelix:acpid:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AF501BE4-AA18-407F-8873-ABFAC8B48314",
              "versionEndIncluding": "2.0.8"
            },
            {
              "criteria": "cpe:2.3:a:tedfelix:acpid:1.0.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82B4C09A-27B5-40C3-BC29-1AF719D15866"
            },
            {
              "criteria": "cpe:2.3:a:tedfelix:acpid:1.0.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE4A0A4D-A705-42D0-B6ED-839AD1E1654D"
            },
            {
              "criteria": "cpe:2.3:a:tedfelix:acpid:2.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31FBDC0D-23D1-4D6A-A04B-42F3044F67D4"
            },
            {
              "criteria": "cpe:2.3:a:tedfelix:acpid:2.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27515319-B40F-46F6-9850-AF56D0DF46E2"
            },
            {
              "criteria": "cpe:2.3:a:tedfelix:acpid:2.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A217BEA-9E4C-4CEF-8AFF-46A01AE5ACA0"
            },
            {
              "criteria": "cpe:2.3:a:tedfelix:acpid:2.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B26E4400-07F3-40F4-8E40-91A9A38BCD9F"
            },
            {
              "criteria": "cpe:2.3:a:tedfelix:acpid:2.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "44949FCD-B2F0-41EE-9714-161740CC734F"
            },
            {
              "criteria": "cpe:2.3:a:tedfelix:acpid:2.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC73131B-B96A-43EA-9854-48D71582FFC3"
            },
            {
              "criteria": "cpe:2.3:a:tedfelix:acpid:2.0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0E5388D-E751-4A75-935F-7B2056F24576"
            },
            {
              "criteria": "cpe:2.3:a:tedfelix:acpid:2.06:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "672CB3CB-4FBD-4B9F-8EBE-2A8D262D19D0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}