The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might allow local users to gain privileges by leveraging access to this account and then waiting for root to execute one of these programs.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-03-12T04:00:00

Updated: 2024-08-05T21:13:49.096Z

Reserved: 2018-03-11T00:00:00

Link: CVE-2017-18225

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-03-12T04:29:00.227

Modified: 2019-10-03T00:03:26.223

Link: CVE-2017-18225

cve-icon Redhat

No data.