Local File Inclusion Vulnerability in Gentoo Portage by Gentoo
CVE-2019-20384

5.5MEDIUM

Key Information:

Vendor

Gentoo

Status
Vendor
CVE Published:
21 January 2020

What is CVE-2019-20384?

Gentoo Portage versions up to 2.3.84 are vulnerable to a local file inclusion issue that allows unauthorized users to manipulate files within the system. By exploiting this vulnerability, attackers with access to the nagios user account can place a Trojan horse plugin in the writable /usr/lib64/nagios/plugins directory. This risk arises from improper permissions that permit the writing of files as a temporary measure during the emake process, subsequently exposing the system to potential compromise due to the execution of malicious code through this Trojan horse.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.