Vulnerabilities > Gentoo > Low

DATE CVE VULNERABILITY TITLE RISK
2020-01-21 CVE-2019-20384 Improper Preservation of Permissions vulnerability in Gentoo Portage
Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to the nagios user account, because this directory is writable in between a call to emake and a call to fowners.
local
low complexity
gentoo CWE-281
2.1
2018-06-04 CVE-2017-18284 Incorrect Permission Assignment for Critical Resource vulnerability in Burp Project Burp
The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL.
local
low complexity
burp-project gentoo CWE-732
3.6
2018-06-04 CVE-2017-18285 Incorrect Permission Assignment for Critical Resource vulnerability in Burp Project Burp
The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain read and write access to arbitrary files by leveraging access to a certain account for a burp-server.conf change.
local
low complexity
burp-project gentoo CWE-732
3.6
2018-03-12 CVE-2017-18226 Incorrect Permission Assignment for Critical Resource vulnerability in Jabberd2
The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script executes a "kill -TERM `cat /var/run/jabber/filename.pid`" command.
local
low complexity
jabberd2 gentoo CWE-732
2.1
2017-06-27 CVE-2004-2778 Permissions, Privileges, and Access Controls vulnerability in Gentoo Portage
Ebuild in Gentoo may change directory and file permissions depending on the order of installed packages, which allows local users to read or write to restricted directories or execute restricted commands via navigating to the affected directories, or executing the affected commands.
local
low complexity
gentoo CWE-264
3.6
2011-03-30 CVE-2011-1155 Resource Management Errors vulnerability in Gentoo Logrotate
The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.
local
gentoo CWE-399
1.9
2009-04-27 CVE-2008-6756 Permissions, Privileges, and Access Controls vulnerability in Zoneminder 1.23.3
ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username and password by reading this file.
local
low complexity
zoneminder gentoo CWE-264
2.1
2008-04-18 CVE-2008-1734 Improper Input Validation vulnerability in Gentoo PHP Toolkit 1.0
Interpretation conflict in PHP Toolkit before 1.0.1 on Gentoo Linux might allow local users to cause a denial of service (PHP outage) and read contents of PHP scripts by creating a file with a one-letter lowercase alphabetic name, which triggers interpretation of a certain unquoted [a-z] argument as a matching shell glob for this name, rather than interpretation as the literal [a-z] regular-expression string, and consequently blocks the launch of the PHP interpreter within the Apache HTTP Server.
local
low complexity
gentoo CWE-20
3.6
2008-03-18 CVE-2008-1383 Cryptographic Issues vulnerability in Gentoo Linux
The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from the binpkg, and causes multiple systems that use this binpkg to have the same SSL key and certificate.
local
gentoo CWE-310
1.9
2007-12-15 CVE-2007-6249 Information Exposure vulnerability in Gentoo Portage 2.0.51.22/2.1.1/2.1.3.10
etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to obtain sensitive information by reading the merge file.
local
low complexity
gentoo CWE-200
2.1