CVE-2017-18240
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
19/03/2018
Last modified:
18/04/2018
Description
The Gentoo app-admin/collectd package before 5.7.2-r1 sets the ownership of PID file directory to the collectd account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL (when the service is stopped).
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
4.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:collectd:collectd:*:*:*:*:*:*:*:* | 5.7.2 (including) | |
| cpe:2.3:a:collectd:collectd:5.7.2:r1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



