CVE-2017-18226 describes a local privilege escalation vulnerability in the Gentoo net-im/jabberd2 package up to version 2.6.1. The vulnerability arises from incorrect ownership of the /var/run/jabber directory, allowing a local attacker with access to the 'jabber' account to modify PID files. This could enable the attacker to terminate arbitrary processes when a root script attempts to kill the jabberd2 service. The vulnerability has a CVSS v3 score of 5.5 (Medium), indicating a low attack complexity and requiring local access, with a high impact on availability. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. It is not listed in CISA's Known Exploited Vulnerabilities Catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.1CPE matchmatch criteria | cpe:2.3:a:jabberd2:jabberd2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.