First published: Mon Mar 12 2018(Updated: )
The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might allow local users to gain privileges by leveraging access to this account and then waiting for root to execute one of these programs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jabberd2 Jabberd2 | <=2.6.1 | |
Gentoo Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2017-18225.
The severity of CVE-2017-18225 is high with a severity value of 7.8.
The net-im/jabberd2 package through version 2.6.1 is affected by CVE-2017-18225.
Local users can gain privileges by leveraging access to the jabber account and then waiting for root to execute one of the vulnerable binaries installed by the Gentoo net-im/jabberd2 package.
No, Gentoo Linux is not vulnerable to CVE-2017-18225.