Local File Inclusion Vulnerability in Gentoo Portage by Gentoo
CVE-2019-20384
5.5MEDIUM
What is CVE-2019-20384?
Gentoo Portage versions up to 2.3.84 are vulnerable to a local file inclusion issue that allows unauthorized users to manipulate files within the system. By exploiting this vulnerability, attackers with access to the nagios user account can place a Trojan horse plugin in the writable /usr/lib64/nagios/plugins directory. This risk arises from improper permissions that permit the writing of files as a temporary measure during the emake process, subsequently exposing the system to potential compromise due to the execution of malicious code through this Trojan horse.