Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Portage | Gentoo | * | 2.0.50 (excluding) |
Portage | Gentoo | 2.0.50 (including) | 2.0.50 (including) |
Linux | Gentoo | 1.4 (including) | 1.4 (including) |
Linux | Gentoo | 1.4-rc1 (including) | 1.4-rc1 (including) |
Linux | Gentoo | 1.4-rc2 (including) | 1.4-rc2 (including) |