{"api_version":"1","generated_at":"2026-07-23T09:31:21+00:00","cve":"CVE-2017-18240","urls":{"html":"https://cve.report/CVE-2017-18240","api":"https://cve.report/api/cve/CVE-2017-18240.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-18240","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-18240"},"summary":{"title":"CVE-2017-18240","description":"The Gentoo app-admin/collectd package before 5.7.2-r1 sets the ownership of PID file directory to the collectd account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL (when the service is stopped).","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-03-19 02:29:00","updated_at":"2018-04-18 16:14:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://bugs.gentoo.org/628540","name":"https://bugs.gentoo.org/628540","refsource":"CONFIRM","tags":["Issue Tracking","Vendor Advisory"],"title":"628540 – (CVE-2017-18240) <app-admin/collectd-5.7.2-r1: privilege escalation via PID file manipulation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/201803-10","name":"GLSA-201803-10","refsource":"GENTOO","tags":["Vendor Advisory"],"title":"collectd: Multiple vulnerabilities (GLSA 201803-10) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/103469","name":"103469","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Gentoo Collectd Package CVE-2017-18240 Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-18240","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-18240","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"18240","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"collectd","cpe5":"collectd","cpe6":"5.7.2","cpe7":"r1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18240","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"collectd","cpe5":"collectd","cpe6":"5.7.2","cpe7":"r1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"18240","vulnerable":"1","versionEndIncluding":"5.7.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"collectd","cpe5":"collectd","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2017-18240","qid":"710277","title":"Gentoo Linux collectd Multiple Vulnerabilities (GLSA 201803-10)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-18240","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Gentoo app-admin/collectd package before 5.7.2-r1 sets the ownership of PID file directory to the collectd account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL (when the service is stopped)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"GLSA-201803-10","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201803-10"},{"name":"103469","refsource":"BID","url":"http://www.securityfocus.com/bid/103469"},{"name":"https://bugs.gentoo.org/628540","refsource":"CONFIRM","url":"https://bugs.gentoo.org/628540"}]}},"nvd":{"publishedDate":"2018-03-19 02:29:00","lastModifiedDate":"2018-04-18 16:14:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:N/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE","baseScore":4.9},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:collectd:collectd:*:*:*:*:*:*:*:*","versionEndIncluding":"5.7.2","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:collectd:collectd:5.7.2:r1:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"18240","Ordinal":"125144","Title":"CVE-2017-18240","CVE":"CVE-2017-18240","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"18240","Ordinal":"1","NoteData":"The Gentoo app-admin/collectd package before 5.7.2-r1 sets the ownership of PID file directory to the collectd account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL (when the service is stopped).","Type":"Description","Title":null},{"CveYear":"2017","CveId":"18240","Ordinal":"2","NoteData":"2018-03-18","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"18240","Ordinal":"3","NoteData":"2018-03-22","Type":"Other","Title":"Modified"}]}}}