CVE-2007-6249: Infoleak
etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to obtain sensitive information by reading the merge file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6249?
CVE-2007-6249 is considered a moderate severity vulnerability due to its potential to expose sensitive information to local users.
How do I fix CVE-2007-6249?
To fix CVE-2007-6249, upgrade your Gentoo Portage to version 2.1.3.11 or later.
What systems are affected by CVE-2007-6249?
CVE-2007-6249 affects Gentoo Linux systems running versions of Portage prior to 2.1.3.11.
What is the impact of CVE-2007-6249?
The impact of CVE-2007-6249 is that weak permissions on merge files may allow local users to read sensitive information unintentionally.
Who can exploit CVE-2007-6249?
CVE-2007-6249 can be exploited by local users on affected systems who can access the merge files.