CVE-2017-18225 Information
Feb 14, 2021
cve
Description
The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd jabberd2-c2s jabberd2-router jabberd2-s2s and jabberd2-sm in /usr/bin owned by the jabber account which might allow local users to gain privileges by leveraging access to this account and then waiting for root to execute one of these programs.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://bugs.gentoo.org/629412
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: