CVE-2017-18226: Medium severity jabberd vulnerability
Published Mar 12, 2018
·Updated
The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script executes a "kill -TERM cat /var/run/jabber/filename.pid" command.
Affected Software
2 affected components
jabberd2 jabberd2<=2.6.1
Gentoo Linux
Event History
Mar 12, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-18226.
2
What is the severity of CVE-2017-18226?
The severity of CVE-2017-18226 is medium (5.5).
3
Which software package is affected by CVE-2017-18226?
The Gentoo net-im/jabberd2 package through 2.6.1 is affected by CVE-2017-18226.
4
What is the impact of CVE-2017-18226?
CVE-2017-18226 allows local users to kill arbitrary processes by leveraging access to the jabber account for PID file modification.
5
Is Gentoo Linux affected by CVE-2017-18226?
No, Gentoo Linux is not affected by CVE-2017-18226.