Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vfqg-qqv4-ghx2

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to obtain sensitive information by reading the merge file.

etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to obtain sensitive information by reading the merge file.

EPSS

Процентиль: 22%
0.00073
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
около 18 лет назад

etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to obtain sensitive information by reading the merge file.

fstec
около 18 лет назад

Уязвимость операционной системы Gentoo Linux, позволяющая злоумышленнику нарушить целостность защищаемой информации

EPSS

Процентиль: 22%
0.00073
Низкий

Дефекты

CWE-200