CVE-2017-18284
Summary
| CVE | CVE-2017-18284 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-04 06:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 628770 – (CVE-2017-18284) <app-backup/burp-2.1.32: privilege escalation via PID file manipulation |
CONFIRM |
bugs.gentoo.org |
Issue Tracking, Third Party Advisory |
| BURP: Multiple vulnerabilities (GLSA 201806-03) — Gentoo Security |
GENTOO |
security.gentoo.org |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710215 Gentoo Linux BURP Multiple Vulnerabilities (GLSA 201806-03)