CVE-2017-18240: Input Validation
The Gentoo app-admin/collectd package before 5.7.2-r1 sets the ownership of PID file directory to the collectd account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL (when the service is stopped).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18240?
CVE-2017-18240 is considered a medium severity vulnerability due to its potential to allow local users to affect process management.
How do I fix CVE-2017-18240?
To fix CVE-2017-18240, upgrade the app-admin/collectd package to version 5.7.2-r1 or later.
What does CVE-2017-18240 allow a malicious user to do?
CVE-2017-18240 may allow a malicious local user to kill arbitrary processes by manipulating PID files.
Which versions of collectd are affected by CVE-2017-18240?
Versions of collectd before 5.7.2-r1 are affected by CVE-2017-18240.
Is CVE-2017-18240 a remote or local vulnerability?
CVE-2017-18240 is a local vulnerability that requires user access to exploit.