Local Privilege Escalation in Gentoo GIMPS Package by Unsafe Command Execution
CVE-2017-14484
7.3HIGH
What is CVE-2017-14484?
The Gentoo GIMPS package prior to version 28.10-r1 contains a vulnerability that enables local users to gain elevated privileges. This occurs due to the execution of an unsafe 'chown -R' command, which can be exploited by creating a hard link under the /var/lib/gimps directory. This oversight allows unauthorized users to manipulate file permissions, posing a significant security risk within the system.