CVE-2019-20384
MEDIUMGentoo Portage < 2.3.84 - Race Condition
Title source: ruleDescription
Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to the nagios user account, because this directory is writable in between a call to emake and a call to fowners.
Scores
CVSS v3
5.5
EPSS
0.0009
EPSS Percentile
25.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-362
Status
published
Affected Products (1)
gentoo/portage
< 2.3.84
Timeline
Published
Jan 21, 2020
Tracked Since
Feb 18, 2026