CVE-2007-6249

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
15/12/2007
Last modified:
09/04/2025

Description

etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original files, which might allow local users to obtain sensitive information by reading the merge file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*
cpe:2.3:a:gentoo:portage:*:*:*:*:*:*:*:* 2.1.3.10 (including)