Vulnerability Name: | CVE-2004-2778 (CCN-134136) | ||||||||||||
Assigned: | 2017-01-28 | ||||||||||||
Published: | 2017-01-28 | ||||||||||||
Updated: | 2017-07-05 | ||||||||||||
Summary: | Ebuild in Gentoo may change directory and file permissions depending on the order of installed packages, which allows local users to read or write to restricted directories or execute restricted commands via navigating to the affected directories, or executing the affected commands. | ||||||||||||
CVSS v3 Severity: | 7.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) 6.3 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:U/RC:R)
7.4 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
| ||||||||||||
CVSS v2 Severity: | 3.6 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2004-2778 Source: CCN Type: oss-sec Mailing List, Sat, 28 Jan 2017 17:12:19 -0500 Re: Gentoo: order of installed packages may result in vary directories permissions, leading to crontab not requiring cron group membership as example Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20170128 Re: Gentoo: order of installed packages may result in vary directories permissions, leading to crontab not requiring cron group membership as example. Source: CONFIRM Type: Vendor Advisory https://bugs.gentoo.org/show_bug.cgi?id=141619 Source: CONFIRM Type: Vendor Advisory https://bugs.gentoo.org/show_bug.cgi?id=396153 Source: CONFIRM Type: Vendor Advisory https://bugs.gentoo.org/show_bug.cgi?id=58611 Source: CONFIRM Type: Vendor Advisory https://bugs.gentoo.org/show_bug.cgi?id=607426 Source: CONFIRM Type: Vendor Advisory https://bugs.gentoo.org/show_bug.cgi?id=607430 Source: XF Type: UNKNOWN gentoo-cve20042778-info-disc(134136) Source: CCN Type: Gentoo Web site gentoo | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |