The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might allow local users to gain privileges by leveraging access to this account and then waiting for root to execute one of these programs.
References
Link Resource
https://bugs.gentoo.org/629412 Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-03-12T04:00:00

Updated: 2018-03-12T04:57:01

Reserved: 2018-03-11T00:00:00


Link: CVE-2017-18225

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-03-12T04:29:00.227

Modified: 2019-10-03T00:03:26.223


Link: CVE-2017-18225

JSON object: View

cve-icon Redhat Information

No data.

CWE