Vulnerability Name: | CVE-2005-0457 (CCN-20348) | ||||||||
Assigned: | 2005-02-14 | ||||||||
Published: | 2005-02-14 | ||||||||
Updated: | 2022-02-28 | ||||||||
Summary: | Opera 7.54 and earlier on Gentoo Linux uses an insecure path for plugins, which could allow local users to gain privileges by inserting malicious libraries into the PORTAGE_TMPDIR (portage) temporary directory. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-427 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: Gentoo bugzilla Web site Bug 81747 - net-www/opera: default plugin search path includes untrusted directory Source: CONFIRM Type: Third Party Advisory, Vendor Advisory http://bugs.gentoo.org/show_bug.cgi?id=81747 Source: MITRE Type: CNA CVE-2005-0457 Source: CCN Type: GLSA-200502-17 Opera: Multiple vulnerabilities Source: GENTOO Type: Patch, Third Party Advisory, Vendor Advisory GLSA-200502-17 Source: CCN Type: Opera Web site Opera Software - The Best Internet Experience Source: CCN Type: OSVDB ID: 15890 Opera Gentoo Linux Plugin Path Subversion Privilege Escalation Source: XF Type: UNKNOWN opera-portagetmpdir-gain-privileges(20348) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |