{"id":"UBUNTU-CVE-2011-1784","details":"The pidfile_write function in core/pidfile.c in keepalived 1.2.2 and earlier uses 0666 permissions for the (1) keepalived.pid, (2) checkers.pid, and (3) vrrp.pid files in /var/run/, which allows local users to kill arbitrary processes by writing a PID to one of these files.","modified":"2025-07-16T07:30:46.204799Z","published":"2011-05-20T22:55:00Z","withdrawn":"2025-07-18T16:42:42Z","upstream":["CVE-2011-1784"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2011-1784"},{"type":"REPORT","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=626281"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2011-1784"}],"affected":[{"package":{"name":"keepalived","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/keepalived@1:1.2.7-1ubuntu1?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.2.7-1ubuntu1"}]}],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"1:1.2.7-1ubuntu1","binary_name":"keepalived"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-1784.json"}},{"package":{"name":"keepalived","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/keepalived@1:1.2.24-1ubuntu0.16.04.1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.2.24-1ubuntu0.16.04.1"}]}],"versions":["1:1.2.19-1","1:1.2.19-1ubuntu0.1","1:1.2.19-1ubuntu0.2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"keepalived","binary_version":"1:1.2.24-1ubuntu0.16.04.1"},{"binary_name":"keepalived-dbgsym","binary_version":"1:1.2.24-1ubuntu0.16.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-1784.json"}},{"package":{"name":"keepalived","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/keepalived@1:1.3.9-1ubuntu0.18.04.1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.3.9-1ubuntu0.18.04.1"}]}],"versions":["1:1.3.2-1build1","1:1.3.9-1","1:1.3.9-1build1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"keepalived","binary_version":"1:1.3.9-1ubuntu0.18.04.1"},{"binary_name":"keepalived-dbgsym","binary_version":"1:1.3.9-1ubuntu0.18.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-1784.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"low"}]}