Vulnerabilities > Gentoo

DATE CVE VULNERABILITY TITLE RISK
2007-12-31 CVE-2007-6337 Unspecified vulnerability in Clam Anti-Virus Clamav 0.91.2
Unspecified vulnerability in the bzip2 decompression algorithm in nsis/bzlib_private.h in ClamAV before 0.92 has unknown impact and remote attack vectors.
network
low complexity
gentoo clam-anti-virus
critical
10.0
2007-12-15 CVE-2007-6249 Information Exposure vulnerability in Gentoo Portage 2.0.51.22/2.1.1/2.1.3.10
etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to obtain sensitive information by reading the merge file.
local
low complexity
gentoo CWE-200
2.1
2007-10-30 CVE-2007-5714 Improper Authentication vulnerability in Gentoo Mldonkey Ebuild 2.9.0
The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote attackers to obtain login access and execute arbitrary code.
network
gentoo CWE-287
6.8
2007-07-27 CVE-2007-3532 Permissions, Privileges, and Access Controls vulnerability in Nvidia Video Driver
NVIDIA drivers (nvidia-drivers) before 1.0.7185, 1.0.9639, and 100.14.11, as used in Gentoo Linux and possibly other distributions, creates /dev/nvidia* device files with insecure permissions, which allows local users to modify video card settings, cause a denial of service (crash or physical video card damage), and obtain sensitive information.
local
low complexity
gentoo nvidia CWE-264
7.2
2007-07-25 CVE-2007-3531 Local Privilege Escalation vulnerability in Gentoo Nvclock 0.7
The set_default_speeds function in backend/backend.c in NVidia NVClock before 0.8b2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/nvclock temporary file.
local
gentoo
6.6
2007-04-24 CVE-2007-2194 Buffer Overflow vulnerability in Gentoo Xnview 1.90.3
Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a crafted XPM file with a long section string.
network
low complexity
gentoo
critical
10.0
2007-04-24 CVE-2007-2173 Unspecified vulnerability in Double Precision Incorporated Courier-Imap
Eval injection vulnerability in (1) courier-imapd.indirect and (2) courier-pop3d.indirect in Courier-IMAP before 4.0.6-r2, and 4.1.x before 4.1.2-r1, on Gentoo Linux allows remote attackers to execute arbitrary commands via the XMAILDIR variable, related to the LOGINRUN variable.
network
low complexity
gentoo double-precision-incorporated
critical
10.0
2007-04-18 CVE-2007-1856 Local Denial of Service vulnerability in Vixie Cron ST_Nlink Check
Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure) by creating hard links, which results in a failed st_nlink check in database.c.
local
low complexity
gentoo paul-vixie
2.1
2007-04-13 CVE-2007-2026 Denial of Service vulnerability in File
The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.
network
low complexity
amavis gentoo
7.8
2007-03-19 CVE-2007-1500 Unspecified vulnerability in Gentoo Linux
The Linux Security Auditing Tool (LSAT) allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using /tmp/lsat1.lsat.
local
low complexity
gentoo
4.3