CVE-2017-18225: High severity jabberd vulnerability
The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might allow local users to gain privileges by leveraging access to this account and then waiting for root to execute one of these programs.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2017-18225.
What is the severity of CVE-2017-18225?
The severity of CVE-2017-18225 is high with a severity value of 7.8.
What software is affected by CVE-2017-18225?
The net-im/jabberd2 package through version 2.6.1 is affected by CVE-2017-18225.
How can local users gain privileges through CVE-2017-18225?
Local users can gain privileges by leveraging access to the jabber account and then waiting for root to execute one of the vulnerable binaries installed by the Gentoo net-im/jabberd2 package.
Is Gentoo Linux vulnerable to CVE-2017-18225?
No, Gentoo Linux is not vulnerable to CVE-2017-18225.