A vulnerability in acpid2 may allow a local attacker to gain escalated privileges.
Package | sys-power/acpid on all architectures |
---|---|
Affected versions | < 2.0.17 |
Unaffected versions | >= 2.0.17 |
acpid2 is a daemon for Advanced Configuration and Power Interface.
acpid2 does not properly use the pidof program in powerbtn.sh.
A local attacker could gain escalated privileges.
There is no known workaround at this time.
All acpid2 users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=sys-power/acpid-2.0.17"
Release date
October 28, 2013
Latest revision
October 28, 2013: 1
Severity
high
Exploitable
local
Bugzilla entries