CVE-2008-4394

Portage < 2.1.4.5 - Untrusted Search Path Vulnerability via Python Module Loading

Title source: llm
STIX 2.1

Description

Multiple untrusted search path vulnerabilities in Portage before 2.1.4.5 include the current working directory in the Python search path, which allows local users to execute arbitrary code via a modified Python module that is loaded by the (1) ys-apps/portage, (2) net-mail/fetchmail, (3) app-editors/leo ebuilds, and other ebuilds.

References (4)

Core 4
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32228
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200810-02.xml
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31670
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45792

Scores

EPSS 0.0006
EPSS Percentile 17.9%

Details

Status published
Products (5)
gentoo/portage 2.0.51.22 r3
gentoo/portage 2.1.1 r2
gentoo/portage 2.1.3.10
gentoo/portage 2.1.3.11
gentoo/portage < 2.1.4.4
Published Oct 10, 2008
Tracked Since Feb 18, 2026