USN-2297-1: acpi-support vulnerability

Ubuntu Security Notice USN-2297-1

22nd July, 2014

acpi-support vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 12.04 LTS


The system could be made to run programs as an administrator.

Software description

  • acpi-support - scripts for handling many ACPI events


CESG discovered that acpi-support incorrectly handled certain privileged
operations when checking for power management daemons. A local attacker
could use this flaw to execute arbitrary code and elevate privileges to

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 12.04 LTS:
acpi-support 0.140.2

To update your system, please follow these instructions:

In general, a standard system update will make all the necessary changes.