CVE-2004-1901

MEDIUM

Portage < 2.0.50-r3 - Arbitrary File Overwrite via Hard Link Attack

Title source: llm
STIX 2.1

Description

Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.

References (4)

Core 4
Core References
Broken Link, Patch, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10060
Vendor Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200404-01.xml
Broken Link, Patch third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11305
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15754

Scores

CVSS v3 5.5
EPSS 0.0010
EPSS Percentile 27.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-59
Status published
Products (3)
gentoo/linux 1.4 (3 CPE variants)
gentoo/portage 2.0.50
gentoo/portage < 2.0.50
Published Dec 31, 2004
Tracked Since Feb 18, 2026