Gentoo 'sys-apps/portage' Search Path Local Privilege Escalation Vulnerability
BID:31670
Info
Gentoo 'sys-apps/portage' Search Path Local Privilege Escalation Vulnerability
| Bugtraq ID: | 31670 |
| Class: | Design Error |
| CVE: |
CVE-2008-4394 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 09 2008 12:00AM |
| Updated: | Oct 09 2008 08:37PM |
| Credit: | Gentoo Security Team |
| Vulnerable: |
Gentoo sys-apps/portage 2.1.4.4 Gentoo sys-apps/portage 2.1.3.11 Gentoo sys-apps/portage 2.1.3.10 |
| Not Vulnerable: |
Gentoo sys-apps/portage 2.1.4.5 |
Discussion
Gentoo 'sys-apps/portage' Search Path Local Privilege Escalation Vulnerability
Gentoo 'sys-apps/portage' is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with superuser privileges. Successfully exploiting this issue will result in the complete compromise of affected computers.
Gentoo 'sys-apps/portage' is prone to a local privilege-escalation vulnerability.
Local attackers can exploit this issue to execute arbitrary code with superuser privileges. Successfully exploiting this issue will result in the complete compromise of affected computers.
Exploit / POC
Gentoo 'sys-apps/portage' Search Path Local Privilege Escalation Vulnerability
An attacker can exploit this issue by enticing an unsuspecting administrator to run the emerge command on certain ebuilds.
An attacker can exploit this issue by enticing an unsuspecting administrator to run the emerge command on certain ebuilds.
Solution / Fix
Gentoo 'sys-apps/portage' Search Path Local Privilege Escalation Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Solution:
The vendor has released fixes. Please see the references for more information.
References
Gentoo 'sys-apps/portage' Search Path Local Privilege Escalation Vulnerability
References:
References: