Vulnerability Description
Untrusted search path vulnerability in OpenLDAP before 2.2.28-r3 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openldap | Openldap | <= 2.2.28_r2 |
References
- http://secunia.com/advisories/18040/Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200512-07.xmlPatch
- http://www.securityfocus.com/bid/15120Patch
- http://secunia.com/advisories/18040/Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200512-07.xmlPatch
- http://www.securityfocus.com/bid/15120Patch
FAQ
What is CVE-2005-4442?
CVE-2005-4442 is a vulnerability with a CVSS score of 7.2 (HIGH). Untrusted search path vulnerability in OpenLDAP before 2.2.28-r3 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build...
How severe is CVE-2005-4442?
CVE-2005-4442 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-4442?
Check the references section above for vendor advisories and patch information. Affected products include: Openldap Openldap.