6.9
CVSSv2

CVE-2008-4394

Published: 10/10/2008 Updated: 08/08/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple untrusted search path vulnerabilities in Portage prior to 2.1.4.5 include the current working directory in the Python search path, which allows local users to execute arbitrary code via a modified Python module that is loaded by the (1) ys-apps/portage, (2) net-mail/fetchmail, (3) app-editors/leo ebuilds, and other ebuilds.

Vulnerable Product Search on Vulmon Subscribe to Product

gentoo portage 2.1.3.11

gentoo portage 2.1.3.10

gentoo portage

gentoo portage 2.1.1

gentoo portage 2.0.51.22