Smokeping: Multiple vulnerabilities — GLSA 202209-08

Multiple vulnerabilities have been discovered in Smokeping, the worst of which could result in root privilege escalation.

Affected packages

net-analyzer/smokeping on all architectures
Affected versions <= 2.7.3-r1
Unaffected versions

Background

Smokeping is a powerful latency measurement tool

Description

Multiple vulnerabilities have been discovered in Smokeping. Please review the CVE identifiers referenced below for details.

Impact

A local attacker which gains access to the smokeping user could gain root privileges.

Workaround

There is no known workaround at this time.

Resolution

Gentoo has discontinued support for Smokeping. We recommend that users remove it:

 # emerge --ask --depclean "net-analyzer/smokeping"
 

References

Release date
September 25, 2022

Latest revision
September 25, 2022: 1

Severity
normal

Exploitable
local

Bugzilla entries