Local Privilege Escalation in Bareos by PID File Manipulation
CVE-2017-14610
What is CVE-2017-14610?
In Bareos, the bareos-dir, bareos-fd, and bareos-sd components have a vulnerability that arises when a PID file is created after a non-root account has dropped privileges. This flaw may permit local users to alter the PID file, which could lead to arbitrary process termination. By leveraging access to the non-root account, an attacker could modify the PID file before a subsequent root script executes a command that terminates processes based on the PID. This situation presents a significant security risk allowing the malicious user to disrupt services or compromise system integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability Reserved
Vulnerability published
