CVE-2017-14484: High severity gentoo sci-mathematics-gimps vulnerability
The Gentoo sci-mathematics/gimps package before 28.10-r1 for Great Internet Mersenne Prime Search (GIMPS) allows local users to gain privileges by creating a hard link under /var/lib/gimps, because an unsafe "chown -R" command is executed.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14484?
CVE-2017-14484 has a medium severity level due to its potential for privilege escalation by local users.
How do I fix CVE-2017-14484?
To fix CVE-2017-14484, update the sci-mathematics/gimps package to version 28.10-r1 or later.
What type of vulnerability is CVE-2017-14484?
CVE-2017-14484 is a privilege escalation vulnerability caused by improper handling of file permissions.
Who is affected by CVE-2017-14484?
Local users on systems running affected versions of Gentoo's sci-mathematics/gimps package are at risk from CVE-2017-14484.
Is CVE-2017-14484 exploitable remotely?
CVE-2017-14484 is not exploitable remotely, as it requires local access to the vulnerable system.