The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might allow local users to gain privileges by leveraging access to this account and then waiting for root to execute one of these programs.
References
Link | Resource |
---|---|
https://bugs.gentoo.org/629412 | Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2018-03-11 21:29
Updated : 2019-10-02 17:03
NVD link : CVE-2017-18225
Mitre link : CVE-2017-18225
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
gentoo
- linux
jabberd2
- jabberd2