CVE-2008-4394
published 2008-10-10CVE-2008-4394: Multiple untrusted search path vulnerabilities in Portage before 2.1.4.5 include the current working directory in the Python search path, which allows local…
PriorityP420medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.34%
25.7th percentile
Multiple untrusted search path vulnerabilities in Portage before 2.1.4.5 include the current working directory in the Python search path, which allows local users to execute arbitrary code via a modified Python module that is loaded by the (1) ys-apps/portage, (2) net-mail/fetchmail, (3) app-editors/leo ebuilds, and other ebuilds.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gentoo | portage | <= 2.1.4.4 | — |
| gentoo | portage | — | — |
| gentoo | portage | — | — |
| gentoo | portage | — | — |
| gentoo | portage | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/32228http://security.gentoo.org/glsa/glsa-200810-02.xmlhttp://www.securityfocus.com/bid/31670https://exchange.xforce.ibmcloud.com/vulnerabilities/45792http://secunia.com/advisories/32228http://security.gentoo.org/glsa/glsa-200810-02.xmlhttp://www.securityfocus.com/bid/31670https://exchange.xforce.ibmcloud.com/vulnerabilities/45792
2008-10-10
Published