CVE-2017-18240

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
19/03/2018
Last modified:
18/04/2018

Description

The Gentoo app-admin/collectd package before 5.7.2-r1 sets the ownership of PID file directory to the collectd account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL (when the service is stopped).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:collectd:collectd:*:*:*:*:*:*:*:* 5.7.2 (including)
cpe:2.3:a:collectd:collectd:5.7.2:r1:*:*:*:*:*:*