Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
event.c in acpid (aka acpid2) before 2.0.11 does not have an appropriate umask setting during execution of event-handler scripts, which might allow local users to (1) perform write operations within directories created by a script, or (2) read files created by a script, via standard filesystem system calls.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
acpid 事件脚本安全漏洞
Vulnerability Description
ACPID是一个灵活、可扩展的ACPI事件递送守护程序。 acpid 2.0.11之前版本中的event.c中存在安全漏洞,该安全漏洞源于在发起事件脚本攻击时acpid未设置文件权限掩码。本地恶意用户利用该漏洞可能泄露敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A