Security Advisory

CVE-2017-18226

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-03-12 04:00:00
Last updated 2024-08-05 21:13:49
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script executes a "kill -TERM `cat /var/run/jabber/filename.pid`" command.