Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Gentoo: GLSA-200505-14 Normal: Cheetah Local Exploit Risk

gentoo
Calendar Grey May 19, 2005
Scroller Gentoo
A moderate severity flaw in Cheetah on Gentoo Linux permits local users to gain escalated privileges. Updates are now available.
Cheetah contains a vulnerability in the module importing code that can allow a local user to gain escalated privileges.

Summary

Gentoo Linux Security Advisory GLSA 200505-14 https://security.gentoo.org/ Severity: Normal Title: Cheetah: Untrusted module search path Date: May 19, 2005 Bugs: #92926 ID: 200505-14

Synopsis ======= Cheetah contains a vulnerability in the module importing code that can allow a local user to gain escalated privileges.
Background ========= Cheetah is a Python powered template engine and code generator.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-python/cheetah < 0.9.17-rc1 >= 0.9.17-rc1
========== Brian Bird discovered that Cheetah searches for modules in the world-writable /tmp directory.
Impact ===== A malicious local user could place a module containing a...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround