Vulnerabilities > Gentoo

DATE CVE VULNERABILITY TITLE RISK
2005-12-16 CVE-2005-4279 Packages Insecure RUNPATH vulnerability in Gentoo Qt-Unixodbc 3.3.3
Untrusted search path vulnerability in Qt-UnixODBC before 3.3.4-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.
local
low complexity
gentoo
7.2
2005-11-23 CVE-2005-3785 Unspecified vulnerability in Gentoo Linux EIX 0.3
Second-order symlink vulnerability in eix-sync.in in Ebuild IndeX (eix) before 0.5.0_pre2 allows local users to overwrite arbitrary files via a symlink attack on the exi.X.sync temporary file, which is processed by the diff-eix program.
network
low complexity
gentoo
5.0
2005-09-28 CVE-2005-2557 Input Validation vulnerability in Mantis
Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE-2005-3090.
network
mantis debian gentoo
4.3
2005-06-10 CVE-2005-1267 Denial Of Service vulnerability in tcpdump BGP Decoding Routines
The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.
network
low complexity
lbl gentoo mandrakesoft redhat trustix
5.0
2005-05-24 CVE-2005-1707 Unspecified vulnerability in Gentoo Linux Webapp-Config 1.10
The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file.
local
low complexity
gentoo
4.6
2005-05-02 CVE-2005-1121 Remote Format String vulnerability in Oops! Proxy Server Auth
Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.
network
low complexity
igor-khasilev gentoo
5.0
2005-05-02 CVE-2005-0988 Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.
local
high complexity
gnu freebsd gentoo redhat trustix turbolinux ubuntu
3.7
2005-05-02 CVE-2005-0427 Remote Security vulnerability in webmin-1.140.ebuild
The ebuild of Webmin before 1.170-r3 on Gentoo Linux includes the encrypted root password in the miniserv.users file when building a tbz2 of the webmin package, which allows remote attackers to obtain and possibly crack the encrypted password.
network
low complexity
gentoo
5.0
2005-05-02 CVE-2005-0077 Insecure Temporary File Creation vulnerability in Libdbi-perl
The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
local
low complexity
debian gentoo redhat ubuntu
2.1
2005-05-02 CVE-2005-0005 Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.
network
low complexity
graphicsmagick imagemagick sgi debian gentoo suse
7.5