CVE Vulnerabilities

CVE-2005-4280

Published: Dec 16, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Untrusted search path vulnerability in CMake before 2.2.0-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.

Affected Software

NameVendorStart VersionEnd Version
CmakeKitware1.4.3 (including)1.4.3 (including)
CmakeKitware1.4.4 (including)1.4.4 (including)
CmakeKitware1.4.5 (including)1.4.5 (including)
CmakeKitware1.4.6 (including)1.4.6 (including)
CmakeKitware1.4.7 (including)1.4.7 (including)
CmakeKitware1.6.0 (including)1.6.0 (including)
CmakeKitware1.6.0_beta1 (including)1.6.0_beta1 (including)
CmakeKitware1.6.0_beta2 (including)1.6.0_beta2 (including)
CmakeKitware1.6.1 (including)1.6.1 (including)
CmakeKitware1.6.2 (including)1.6.2 (including)
CmakeKitware1.6.3 (including)1.6.3 (including)
CmakeKitware1.6.4 (including)1.6.4 (including)
CmakeKitware1.6.5 (including)1.6.5 (including)
CmakeKitware1.6.6 (including)1.6.6 (including)
CmakeKitware1.6.7 (including)1.6.7 (including)
CmakeKitware1.8.0 (including)1.8.0 (including)
CmakeKitware1.8.1 (including)1.8.1 (including)
CmakeKitware1.8.2 (including)1.8.2 (including)
CmakeKitware1.8.3 (including)1.8.3 (including)
CmakeKitware2.0.0 (including)2.0.0 (including)
CmakeKitware2.0.1 (including)2.0.1 (including)
CmakeKitware2.0.2 (including)2.0.2 (including)
CmakeKitware2.0.3 (including)2.0.3 (including)
CmakeKitware2.0.4 (including)2.0.4 (including)
CmakeKitware2.0.5 (including)2.0.5 (including)
CmakeKitware2.0.6 (including)2.0.6 (including)
CmakeKitware2.2.0 (including)2.2.0 (including)

References