CVE-2004-1901

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
31/12/2004
Last modified:
03/04/2025

Description

Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gentoo:portage:*:*:*:*:*:*:*:* 2.0.50 (excluding)
cpe:2.3:a:gentoo:portage:2.0.50:-:*:*:*:*:*:*
cpe:2.3:o:gentoo:linux:1.4:-:*:*:*:*:*:*
cpe:2.3:o:gentoo:linux:1.4:rc1:*:*:*:*:*:*
cpe:2.3:o:gentoo:linux:1.4:rc2:*:*:*:*:*:*