René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

89 lines
2.5 KiB
JSON

{
"id": "CVE-2017-20147",
"sourceIdentifier": "cve@mitre.org",
"published": "2022-09-20T18:15:09.953",
"lastModified": "2022-10-01T02:33:28.140",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript uses a PID file that is writable by the smokeping user. By writing arbitrary PIDs to that file, the smokeping user can cause a denial of service to arbitrary PIDs when the service is stopped."
},
{
"lang": "es",
"value": "En el paquete ebuild versiones hasta smokeping-2.7.3-r1 para SmokePing en Gentoo, el initscript usa un archivo PID que es escribible por el usuario smokeping. Al escribir PIDs arbitrarios en ese archivo, el usuario smokeping puede causar una denegaci\u00f3n de servicio a PIDs arbitrarios cuando el servicio es detenido"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:smokeping:smokeping:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.7.3-r1",
"matchCriteriaId": "B6E41EEC-A9B0-4852-9452-EEA3F55A2D71"
}
]
}
]
}
],
"references": [
{
"url": "https://bugs.gentoo.org/631140",
"source": "cve@mitre.org",
"tags": [
"Exploit",
"Issue Tracking",
"Third Party Advisory"
]
},
{
"url": "https://security.gentoo.org/glsa/202209-08",
"source": "cve@mitre.org",
"tags": [
"Third Party Advisory"
]
}
]
}