Vulnerabilities > Gentoo > Linux > Low

DATE CVE VULNERABILITY TITLE RISK
2018-06-04 CVE-2017-18284 Incorrect Permission Assignment for Critical Resource vulnerability in Burp Project Burp
The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL.
local
low complexity
burp-project gentoo CWE-732
3.6
2018-06-04 CVE-2017-18285 Incorrect Permission Assignment for Critical Resource vulnerability in Burp Project Burp
The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain read and write access to arbitrary files by leveraging access to a certain account for a burp-server.conf change.
local
low complexity
burp-project gentoo CWE-732
3.6
2018-03-12 CVE-2017-18226 Incorrect Permission Assignment for Critical Resource vulnerability in Jabberd2
The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script executes a "kill -TERM `cat /var/run/jabber/filename.pid`" command.
local
low complexity
jabberd2 gentoo CWE-732
2.1
2009-04-27 CVE-2008-6756 Permissions, Privileges, and Access Controls vulnerability in Zoneminder 1.23.3
ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username and password by reading this file.
local
low complexity
zoneminder gentoo CWE-264
2.1
2008-04-18 CVE-2008-1734 Improper Input Validation vulnerability in Gentoo PHP Toolkit 1.0
Interpretation conflict in PHP Toolkit before 1.0.1 on Gentoo Linux might allow local users to cause a denial of service (PHP outage) and read contents of PHP scripts by creating a file with a one-letter lowercase alphabetic name, which triggers interpretation of a certain unquoted [a-z] argument as a matching shell glob for this name, rather than interpretation as the literal [a-z] regular-expression string, and consequently blocks the launch of the PHP interpreter within the Apache HTTP Server.
local
low complexity
gentoo CWE-20
3.6
2008-03-18 CVE-2008-1383 Cryptographic Issues vulnerability in Gentoo Linux
The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from the binpkg, and causes multiple systems that use this binpkg to have the same SSL key and certificate.
local
gentoo CWE-310
1.9
2007-12-15 CVE-2007-6249 Information Exposure vulnerability in Gentoo Portage 2.0.51.22/2.1.1/2.1.3.10
etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to obtain sensitive information by reading the merge file.
local
low complexity
gentoo CWE-200
2.1
2007-04-18 CVE-2007-1856 Local Denial of Service vulnerability in Vixie Cron ST_Nlink Check
Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure) by creating hard links, which results in a failed st_nlink check in database.c.
local
low complexity
gentoo paul-vixie
2.1
2005-05-02 CVE-2005-0077 Insecure Temporary File Creation vulnerability in Libdbi-perl
The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
local
low complexity
debian gentoo redhat ubuntu
2.1
2005-05-02 CVE-2005-0988 Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.
local
high complexity
gnu freebsd gentoo redhat trustix turbolinux ubuntu
3.7