Security News

Exploits Discovered - Published CVE-2017-14730

September 25, 2017
All press releases
Security News
September 25, 2017
Title: Gentoo logstash-bin root privilege escalation through recursive chown
Title: Gentoo logstash-bin root privilege escalation through recursive chown
Author: Michael Orlitzky
Fixed in: Versions 5.5.3 and 5.6.1; commits bbd6cb3 and 18f97c8

Summary

Older Gentoo logstash-bin packages ran a recursive chown over a directory in a privileged service path. A local attacker able to place a hard link there could redirect the ownership change to a sensitive file and obtain root privileges.

Learn more

Michael Orlitzky’s detailed advisory provides the full technical disclosure and remediation references for CVE-2017-14730.

What is CVE?

Common Vulnerabilities and Exposures (CVE) provides standard public identifiers for known cybersecurity vulnerabilities. MITRE maintains the CVE program and coordinates its vulnerability-identification ecosystem in the public interest.

About Metro Data, Inc.

Founded in 1994, Metro Data, Inc. is an information-systems and services firm that works exclusively with business clients to develop and apply technology solutions aligned with client goals.
Metro Data’s end-to-end experience helps customers keep pace with changing technology, secure systems, reduce costs, and improve information-system performance.

About the CVE author, Michael J. Orlitzky

Michael J. Orlitzky is a long-time Metro Data technical leader with a Ph.D. in mathematics who has discovered and helped remediate vulnerabilities in operating systems and application software, with research recognized by industry and academic peers.
Related references
CVE-2017-14730 details
Trusted. Experienced. Personally accountable.
Metro Data, Inc.
© 2026 Metro Data, Inc. All rights reserved.