CVE-2017-18225
Last modified
CVE-2017-18225 is a vulnerability of currently unknown severity. The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might allow local users to gain privileges by leveraging access to this account and then waiting for root to execute one of these programs.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might allow local users to gain privileges by leveraging access to this account and then waiting for root to execute one of these programs.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jabberd2 | Jabberd2 | <= 2.6.1 |
References
- https://bugs.gentoo.org/629412Issue Tracking, Third Party Advisory
- https://bugs.gentoo.org/629412Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-18225?
How severe is CVE-2017-18225?
How do I fix CVE-2017-18225?
Are you affected by CVE-2017-18225?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
