CVE-2004-2778: High severity Gentoo portage vulnerability
Published Jun 27, 2017
·Updated
Ebuild in Gentoo may change directory and file permissions depending on the order of installed packages, which allows local users to read or write to restricted directories or execute restricted commands via navigating to the affected directories, or executing the affected commands.
Affected Software
1 affected component
Gentoo portage
Event History
Jun 27, 2017
CVE Published
08:29 PM
Jun 28, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2778?
CVE-2004-2778 is considered a medium severity vulnerability.
2
How do I fix CVE-2004-2778?
To fix CVE-2004-2778, ensure that proper directory and file permissions are configured for affected packages.
3
Who is affected by CVE-2004-2778?
CVE-2004-2778 affects local users on Gentoo systems with improperly configured package installations.
4
What type of vulnerability is CVE-2004-2778?
CVE-2004-2778 is a local privilege escalation vulnerability.
5
Can CVE-2004-2778 allow unauthorized access?
Yes, CVE-2004-2778 can allow unauthorized users to read or write to restricted directories.