CVE-2017-18240
Last modified
CVE-2017-18240 is a vulnerability of currently unknown severity. The Gentoo app-admin/collectd package before 5.7.2-r1 sets the ownership of PID file directory to the collectd account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL (when the service is stopped).. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
The Gentoo app-admin/collectd package before 5.7.2-r1 sets the ownership of PID file directory to the collectd account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL (when the service is stopped).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Collectd | Collectd | <= 5.7.2 | — |
| Collectd | Collectd | 5.7.2 | R1 |
References
- http://www.securityfocus.com/bid/103469Third Party Advisory, VDB Entry
- https://bugs.gentoo.org/628540Issue Tracking, Vendor Advisory
- https://security.gentoo.org/glsa/201803-10Vendor Advisory
- http://www.securityfocus.com/bid/103469Third Party Advisory, VDB Entry
- https://bugs.gentoo.org/628540Issue Tracking, Vendor Advisory
- https://security.gentoo.org/glsa/201803-10Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-18240?
How severe is CVE-2017-18240?
How do I fix CVE-2017-18240?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-18235An issue was discovered in Exempi before 2.4.3. The VPXChunk…
- CVE-2017-18236An issue was discovered in Exempi before 2.4.4. The ASF_Supp…
- CVE-2017-18237An issue was discovered in Exempi before 2.4.3. The PostScri…
- CVE-2017-18238An issue was discovered in Exempi before 2.4.4. The TradQT_M…
- CVE-2017-18239A time-sensitive equality check on the JWT signature in the …
- CVE-2017-1824Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-18241fs/f2fs/segment.c in the Linux kernel before 4.13 allows loc…
- CVE-2017-18242The apply_dependent_coupling function in libavcodec/aacdec.c…
- CVE-2017-18243The unpack_parse_unit function in libavcodec/dirac_parser.c …
- CVE-2017-18244The stereo_processing function in libavcodec/aacps.c in Liba…
- CVE-2017-18245The mpc8_probe function in libavformat/mpc8.c in Libav 12.2 …
- CVE-2017-18246The pcm_encode_frame function in libavcodec/pcm.c in Libav 1…
Are you affected by CVE-2017-18240?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
