Lucene search

K
cveMitreCVE-2008-4394
HistoryOct 10, 2008 - 10:30 a.m.

CVE-2008-4394

2008-10-1010:30:05
mitre
web.nvd.nist.gov
26
security
vulnerability
portage
python
search path
arbitrary code
ebuilds

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.1

Confidence

Low

EPSS

0.001

Percentile

29.6%

Multiple untrusted search path vulnerabilities in Portage before 2.1.4.5 include the current working directory in the Python search path, which allows local users to execute arbitrary code via a modified Python module that is loaded by the (1) ys-apps/portage, (2) net-mail/fetchmail, (3) app-editors/leo ebuilds, and other ebuilds.

Affected configurations

Nvd
Node
gentooportageRange≀2.1.4.4
OR
gentooportageMatch2.0.51.22r3
OR
gentooportageMatch2.1.1r2
OR
gentooportageMatch2.1.3.10
OR
gentooportageMatch2.1.3.11
VendorProductVersionCPE
gentooportage*cpe:2.3:a:gentoo:portage:*:*:*:*:*:*:*:*
gentooportage2.0.51.22cpe:2.3:a:gentoo:portage:2.0.51.22:r3:*:*:*:*:*:*
gentooportage2.1.1cpe:2.3:a:gentoo:portage:2.1.1:r2:*:*:*:*:*:*
gentooportage2.1.3.10cpe:2.3:a:gentoo:portage:2.1.3.10:*:*:*:*:*:*:*
gentooportage2.1.3.11cpe:2.3:a:gentoo:portage:2.1.3.11:*:*:*:*:*:*:*

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.1

Confidence

Low

EPSS

0.001

Percentile

29.6%