
CVE-2017-18284 – Gentoo Linux Security Advisory 201806-03
https://notcve.org/view.php?id=CVE-2017-18284
04 Jun 2018 — The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL. El paquete app-backup/burp de Gentoo, en versiones anteriores a la 2.1.32, establece la propiedad del directorio de archivos PID en la cuenta burp, lo que podría permitir que usuarios locales finalicen procesos arbitrarios aprovechando el... • https://bugs.gentoo.org/628770 • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2017-18285 – Gentoo Linux Security Advisory 201904-05
https://notcve.org/view.php?id=CVE-2017-18285
04 Jun 2018 — The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain read and write access to arbitrary files by leveraging access to a certain account for a burp-server.conf change. El paquete app-backup/burp de Gentoo, en versiones anteriores a la 2.1.32, tiene la propiedad incorrecta del directorio /etc/burp, que podría permitir que usuarios locales obtengan acceso de lectura y escritura a archivos arbitrarios aprovechando el a... • https://bugs.gentoo.org/641842 • CWE-732: Incorrect Permission Assignment for Critical Resource •