The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might allow local users to gain privileges by leveraging access to this account and then waiting for root to execute one of these programs.
References
Link | Resource |
---|---|
https://bugs.gentoo.org/629412 | Issue Tracking Third Party Advisory |
https://bugs.gentoo.org/629412 | Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 03:19
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugs.gentoo.org/629412 - Issue Tracking, Third Party Advisory |
Information
Published : 2018-03-12 04:29
Updated : 2024-11-21 03:19
NVD link : CVE-2017-18225
Mitre link : CVE-2017-18225
CVE.ORG link : CVE-2017-18225
JSON object : View
Products Affected
gentoo
- linux
jabberd2
- jabberd2
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource