PoC Index

CVE-2019-20384

MEDIUM 5.5EPSS 0.3%

Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to the nagios user account, because this directory is writable in between a call to emake and a call to fowners.

CVSS v3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0
2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
EPSS
0.27% chance of exploitation in the next 30 days, 19th percentile
Published
2020-01-20
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related