ACPId Service Vulnerability Analysis and Processing

Source: Internet
Author: User

ACPI-Advanced Configuration and Power Interface, indicating Advanced Configuration and Power management interfaces. D Indicates deamon. The acpid is the ACPI event daemon. That is, the message process of acpi. A service program used to control, obtain, and manage the status of acpi.

Cause of ACPId vulnerability:
Design Error

Impact System
ACPIDACPID1.0.8
+ S. u. S. E. LinuxPersonal9.2
ACPIDACPID1.0.3
+ S. u. S. E. LinuxPersonal9.2
ACPIDACPID1.0.1
+ S. u. S. E. Linux8.1
+ S. u. S. E. LinuxPersonal9.1
+ S. u. S. E. LinuxPersonal9.0x86 _ 64
+ S. u. S. E. LinuxPersonal9.0
+ S. u. S. E. LinuxPersonal8.2
Unaffected System
ACPIDACPID1.0.10

Hazards
Local attackers can exploit this vulnerability to launch DoS attacks on applications.

Attack Conditions
Attackers must access the acpid system.

Vulnerability Information
Acpid is an ACPI event delivery daemon in linux.
Acpid has a denial of service attack. Local attackers can exploit this vulnerability to crash the application.
By not disabling the opened UNIX socket, even if the socket on the other end has been closed), when the Acpid daemon processes error conditions, it will enter an infinite loop. If attackers exhaust a large number of available sockets to open to acpid, too many files are opened, and the daemon enters an infinite loop, consuming a lot of CPU time and blocking other legitimate processes from communicating with acpid.

ACPId Test Method

ACPId vendor solutions
Upgrade to the latest program:
ACPIDACPID1.0.1
ACPIDacpid-1.0.10.tar.gz
Http://sourceforge.net/project/downloading.php? Group_id1_33140&filename=acpid-1.0.10.tar.gz & a = 32826711
ACPIDACPID1.0.3
ACPIDacpid-1.0.10.tar.gz
Http://sourceforge.net/project/downloading.php? Group_id1_33140&filename=acpid-1.0.10.tar.gz & a = 32826711
ACPIDACPID1.0.8
ACPIDacpid-1.0.10.tar.gz
Http://sourceforge.net/project/downloading.php? Group_id1_33140&filename=acpid-1.0.10.tar.gz & a = 32826711

ACPId vulnerability provider
RedHatbugreport

ACPId vulnerability message Link
Https://bugzilla.redhat.com/show_bug.cgi? Id = 494443

ACPId vulnerability Message Title
Bug494443-(CVE-2009-0798) CVE-2009-0798acpid: toomanyopenfilesDoS

Source: http://www.venustech.com.cn/

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.