ZeroHour

CVE-2019-20384

PoC ×2
CVSS 3.1
5.5 medium
EPSS
<1%p19
Published
()
Modified
Description

Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to the nagios user account, because this directory is writable in between a call to emake and a call to fowners.

Vendors
gentoo
Products
portage
Weakness
CWE-362
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.