Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-18240

Опубликовано: 19 мар. 2018
Источник: nvd
CVSS3: 5.5
CVSS2: 4.9
EPSS Низкий

Описание

The Gentoo app-admin/collectd package before 5.7.2-r1 sets the ownership of PID file directory to the collectd account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL (when the service is stopped).

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:collectd:collectd:*:*:*:*:*:*:*:*
Версия до 5.7.2 (включая)
Конфигурация 2
cpe:2.3:a:collectd:collectd:5.7.2:r1:*:*:*:*:*:*

EPSS

Процентиль: 12%
0.0004
Низкий

5.5 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

The Gentoo app-admin/collectd package before 5.7.2-r1 sets the ownership of PID file directory to the collectd account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL (when the service is stopped).

CVSS3: 5.5
debian
почти 8 лет назад

The Gentoo app-admin/collectd package before 5.7.2-r1 sets the ownersh ...

CVSS3: 5.5
github
больше 3 лет назад

The Gentoo app-admin/collectd package before 5.7.2-r1 sets the ownership of PID file directory to the collectd account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL (when the service is stopped).

EPSS

Процентиль: 12%
0.0004
Низкий

5.5 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-20