CVE-2017-18284

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/06/2018
Last modified:
03/10/2019

Description

The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:burp_project:burp:*:*:*:*:*:*:*:* 2.1.32 (excluding)
cpe:2.3:o:gentoo:linux:-:*:*:*:*:*:*:*