Gentoo GIMPS EBuild Insecure Default Permissions Vulnerability
BID:11698
Info
Gentoo GIMPS EBuild Insecure Default Permissions Vulnerability
| Bugtraq ID: | 11698 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 17 2004 12:00AM |
| Updated: | Nov 17 2004 12:00AM |
| Credit: | This vulnerability was announced by the vendor. |
| Vulnerable: |
Gentoo Linux |
| Not Vulnerable: | |
Discussion
Gentoo GIMPS EBuild Insecure Default Permissions Vulnerability
The Gentoo GIMPS eBuild package is reported prone to a weak default permissions vulnerability.
A local attacker may exploit this vulnerability to escalate privileges.
The Gentoo GIMPS eBuild package is reported prone to a weak default permissions vulnerability.
A local attacker may exploit this vulnerability to escalate privileges.
Exploit / POC
Gentoo GIMPS EBuild Insecure Default Permissions Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Gentoo GIMPS EBuild Insecure Default Permissions Vulnerability
Solution:
Gentoo has released an advisory (GLSA 200411-26) to address this and other related issues. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=app-sci/gimps-23.9-r1"
Solution:
Gentoo has released an advisory (GLSA 200411-26) to address this and other related issues. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=app-sci/gimps-23.9-r1"
References
Gentoo GIMPS EBuild Insecure Default Permissions Vulnerability
References:
References: