UBUNTU-CVE-2017-14102
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-14102
Summary:
Details: MIMEDefang 2.80 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by the init-script.in and mimedefang-init.in scripts.
References: https://ubuntu.com/security/CVE-2017-14102, http://lists.roaringpenguin.com/pipermail/mimedefang/2017-August/038077.html, http://lists.roaringpenguin.com/pipermail/mimedefang/2017-August/038085.html, https://www.cve.org/CVERecord?id=CVE-2017-14102
Affected packages
Package
Name: mimedefang
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
