CVE-2011-4578 describes a vulnerability in acpid (aka acpid2) before version 2.0.11, specifically within the event.c component. The flaw stems from an inappropriate umask setting during the execution of event-handler scripts, affecting tedfelix acpid2. This allows local users to potentially perform unauthorized write operations in script-created directories or read files generated by scripts through standard filesystem calls. The vulnerability has a CVSS score of 4.6 (AV:L/AC:L/Au:N/C:P/I:P/A:P), indicating a low severity. It requires local access and low attack complexity, with potential impacts on confidentiality, integrity, and availability. The EPSS score is very low at 0.00078, and its FAUCET Risk Score is 13/100. There is no evidence of active exploitation, and no exploit code is available in Metasploit, Nuclei, or ExploitDB. The CVE is not listed in the KEV catalog and has received no community discussion or media coverage, suggesting a lack of widespread attention or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.10CPE matchmatch criteria | cpe:2.3:a:tedfelix:acpid2:*:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:tedfelix:acpid2:2.0.0:*:*:*:*:*:*:* | ||
2.0.1CPE matchmatch criteria | cpe:2.3:a:tedfelix:acpid2:2.0.1:*:*:*:*:*:*:* | ||
2.0.2CPE matchmatch criteria | cpe:2.3:a:tedfelix:acpid2:2.0.2:*:*:*:*:*:*:* | ||
2.0.3CPE matchmatch criteria | cpe:2.3:a:tedfelix:acpid2:2.0.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.