The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL.
                
            References
                    | Link | Resource | 
|---|---|
| https://bugs.gentoo.org/628770 | Issue Tracking Third Party Advisory | 
| https://security.gentoo.org/glsa/201806-03 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    No history.
Information
                Published : 2018-06-04 06:29
Updated : 2019-10-03 00:03
NVD link : CVE-2017-18284
Mitre link : CVE-2017-18284
CVE.ORG link : CVE-2017-18284
JSON object : View
Products Affected
                burp_project
- burp
gentoo
- linux
CWE
                
                    
                        
                        CWE-732
                        
            Incorrect Permission Assignment for Critical Resource
