The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might allow local users to gain privileges by leveraging access to this account and then waiting for root to execute one of these programs.
References
Link | Resource |
---|---|
https://bugs.gentoo.org/629412 | Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2018-03-12 04:29
Updated : 2019-10-03 00:03
NVD link : CVE-2017-18225
Mitre link : CVE-2017-18225
CVE.ORG link : CVE-2017-18225
JSON object : View
Products Affected
jabberd2
- jabberd2
gentoo
- linux
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource