CVE-2007-6249
Summary
| CVE | CVE-2007-6249 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-12-15 01:46:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to obtain sensitive information by reading the merge file. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:L/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Gentoo Bug 193589 - sys-apps/portage < 2.1.3.11 File disclosure when when merging with etc-update (CVE-2007-6249) | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | Exploit |
| Gentoo Portage May Disclose Information to Local Users - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Portage 'etc-update' Local Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Gentoo Linux Documentation -- Portage: Information disclosure | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| osvdb.org/42636 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Gentoo Portage "etc-update" Information Disclosure - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| sources.gentoo.org/viewcvs.py/portage | af854a3a-2127-422b-91ae-364da2661108 | sources.gentoo.org | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.