Vulnerability Name: | CVE-2007-6249 (CCN-39035) | ||||||||
Assigned: | 2007-12-13 | ||||||||
Published: | 2007-12-13 | ||||||||
Updated: | 2017-08-08 | ||||||||
Summary: | etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to obtain sensitive information by reading the merge file. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N) 1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CONFIRM Type: Exploit http://bugs.gentoo.org/show_bug.cgi?id=193589 Source: MITRE Type: CNA CVE-2007-6249 Source: OSVDB Type: UNKNOWN 42636 Source: CCN Type: SA28094 Gentoo Portage "etc-update" Information Disclosure Source: SECUNIA Type: UNKNOWN 28094 Source: CCN Type: SECTRACK ID: 1019097 Gentoo Portage May Disclose Information to Local Users Source: CONFIRM Type: Exploit http://sources.gentoo.org/viewcvs.py/portage?rev=7799&view=rev Source: CCN Type: GLSA-200712-11 Portage: Information disclosure Source: GENTOO Type: UNKNOWN GLSA-200712-11 Source: CCN Type: OSVDB ID: 42636 Gentoo Linux etc-update Permission Weakness Local Information Disclosure Source: BID Type: UNKNOWN 26864 Source: CCN Type: BID-26864 Portage 'etc-update' Local Information Disclosure Vulnerability Source: SECTRACK Type: UNKNOWN 1019097 Source: XF Type: UNKNOWN portage-etcupdate-information-disclosure(39035) Source: XF Type: UNKNOWN portage-etcupdate-information-disclosure(39035) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |