samples/powerbtn/powerbtn.sh in acpid (aka acpid2) 2.0.16 and earlier uses the pidof program incorrectly, which allows local users to gain privileges by running a program with the name kded4 and a DBUS_SESSION_BUS_ADDRESS environment variable containing commands.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://bugs.launchpad.net/ubuntu/+source/acpid/+bug/893821 |     | 
History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2012-08-29T22:00:00Z
Updated: 2024-09-17T04:18:48.168Z
Reserved: 2011-07-19T00:00:00Z
Link: CVE-2011-2777
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Deferred
Published: 2012-08-29T22:55:01.160
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-2777
 Redhat
                        Redhat
                    No data.