CVE-2011-2777
EPSS 0.31%
Description
samples/powerbtn/powerbtn.sh in acpid (aka acpid2) 2.0.16 and earlier uses the pidof program incorrectly, which allows local users to gain privileges by running a program with the name kded4 and a DBUS_SESSION_BUS_ADDRESS environment variable containing commands.
How to fix CVE-2011-2777
To remediate CVE-2011-2777, upgrade the affected package to a fixed version below.
- Debian/acpid—upgrade to 1:2.0.14-1 or later
Is CVE-2011-2777 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1:2.0.14-1