CVE-2017-14730

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
7.2
HIGH
Affected
1
PROJECT

Description

The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to a $LS_USER account for creation of a hard link.

[MIRROR] Official Gentoo ebuild repository
GitHubGitHub
2.2K