CVE-2017-14159
published 2017-09-05CVE-2017-14159: slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary…
PriorityP421medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.35%
27.2th percentile
slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by openldap-initscript.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openldap | — | — |
| openldap | openldap | <= 2.4.45 | — |
| oracle | blockchain_platform | < 21.1.2 | 21.1.2 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:N/A:P
osv4.7MEDIUM
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openldap: Privilege escalation via PID file manipulation
vendor_redhat·2017-07-28·CVSS 4.7
CVE-2017-14159 [MEDIUM] CWE-377 openldap: Privilege escalation via PID file manipulation
openldap: Privilege escalation via PID file manipulation
slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by openldap-initscript.
Statement: As per upstream this bug can be used only when additional major flaws are found in the slapd binary like the ones caused by heap-based buffer overflows etc. Based on this argument, Red Hat Product Security does not consider this to be a security flaw.
Package: openldap (Red Hat Enterprise Linux 5) - Not affected
Package: compat-openldap (Red Hat Enterprise Linux 6) - Not affected
Packa
Debian
CVE-2017-14159: openldap - slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privilege...
vendor_debian·2017·CVSS 4.7
CVE-2017-14159 [MEDIUM] CVE-2017-14159: openldap - slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privilege...
slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by openldap-initscript.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-xxfr-gfjr-h844: slapd in OpenLDAP 2
ghsa_unreviewed·2022-05-13
CVE-2017-14159 [MEDIUM] CWE-665 GHSA-xxfr-gfjr-h844: slapd in OpenLDAP 2
slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by openldap-initscript.
OSV
CVE-2017-14159: slapd in OpenLDAP 2
osv·2017-09-05·CVSS 4.7
CVE-2017-14159 [MEDIUM] CVE-2017-14159: slapd in OpenLDAP 2
slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by openldap-initscript.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-14159 openldap: Privilege escalation via PID file manipulation
bugzilla·2017-09-06·CVSS 4.7
CVE-2017-14159 [MEDIUM] CVE-2017-14159 openldap: Privilege escalation via PID file manipulation
CVE-2017-14159 openldap: Privilege escalation via PID file manipulation
slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by openldap-initscript.
This represents a minor security issue; additional factors are needed to make it exploitable.
References:
http://www.openldap.org/its/index.cgi?findid=8703
Discussion:
Created openldap tracking bugs for this issue:
Affects: fedora-all [bug 1488752]
---
As per upstream:
"If I understood you correctly, "Additional factors are needed" basically means you have to find a code execu
Bugzilla
CVE-2017-14159 openldap: Privilege escalation via PID file manipulation [fedora-all]
bugzilla·2017-09-06·CVSS 4.7
CVE-2017-14159 [MEDIUM] CVE-2017-14159 openldap: Privilege escalation via PID file manipulation [fedora-all]
CVE-2017-14159 openldap: Privilege escalation via PID file manipulation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
2017-09-05
Published