Get a Pentest and security assessment of your IT network.

Advisories

Gentoo Linux Security Advisory 200810-2

Gentoo Linux Security Advisory GLSA 200810-02 – A search path vulnerability in Portage allows local attackers to execute commands with root privileges if emerge is called from untrusted directories. The Gentoo Security Team discovered that several ebuilds, such as sys-apps/portage, net-mail/fetchmail or app-editors/leo execute Python code using python -c, which includes the current working directory in Python’s module search path. For several ebuild functions, Portage did not change the working directory from emerge’s working directory. Versions less than 2.1.4.5 are affected.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/70756/glsa-200810-02.txt

Source: https://packetstormsecurity.com/files/70756/Gentoo-Linux-Security-Advisory-200810-2.html

Related posts
Advisories

LynX-adv4_SignatureDB.txt

Advisories

Secunia Security Advisory 16497

Advisories

Secunia Security Advisory 19451

Advisories

Debian Linux Security Advisory 1187-1