The Gentoo app-backup/burp package prior to 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
burp_project burp |