CVE-2008-4394
Portage < 2.1.4.5 - Untrusted Search Path Vulnerability via Python Module Loading
Title source: llmDescription
Multiple untrusted search path vulnerabilities in Portage before 2.1.4.5 include the current working directory in the Python search path, which allows local users to execute arbitrary code via a modified Python module that is loaded by the (1) ys-apps/portage, (2) net-mail/fetchmail, (3) app-editors/leo ebuilds, and other ebuilds.
References (4)
Core 4
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/32228
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200810-02.xml
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/31670
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45792
Scores
EPSS
0.0006
EPSS Percentile
17.9%
Details
Status
published
Products (5)
gentoo/portage
2.0.51.22 r3
gentoo/portage
2.1.1 r2
gentoo/portage
2.1.3.10
gentoo/portage
2.1.3.11
gentoo/portage
< 2.1.4.4
Published
Oct 10, 2008
Tracked Since
Feb 18, 2026