Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.54540
Category:Gentoo Local Security Checks
Title:Gentoo Security Advisory GLSA 200404-01 (Portage)
Summary:The remote host is missing updates announced in;advisory GLSA 200404-01.
Description:Summary:
The remote host is missing updates announced in
advisory GLSA 200404-01.

Vulnerability Insight:
A flaw has been found in the temporary file handling algorithms for the
sandboxing code used within Portage. Lockfiles created during normal
Portage operation of portage could be manipulated by local users resulting
in the truncation of hard linked files, causing a Denial of Service attack
on the system.

Solution:
Users should upgrade to Portage 2.0.50-r3 or later:

# emerge sync

# emerge -pv '>=sys-apps/portage-2.0.50-r3'
# emerge '>=sys-apps/portage-2.0.50-r3'

CVSS Score:
4.6

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-1901
BugTraq ID: 10060
http://www.securityfocus.com/bid/10060
http://security.gentoo.org/glsa/glsa-200404-01.xml
http://secunia.com/advisories/11305
XForce ISS Database: portage-lockfile-hardlink(15754)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15754
CopyrightCopyright (C) 2008 E-Soft Inc.

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.