Medium severity5.5NVD Advisory· Published Jan 21, 2020· Updated Jun 17, 2026
CVE-2019-20384
CVE-2019-20384
Description
Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to the nagios user account, because this directory is writable in between a call to emake and a call to fowners.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:gentoo:portage:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gentoo:portage:*:*:*:*:*:*:*:*range: <=2.3.84
- (no CPE)range: <=2.3.84
- Gentoo/Portagedescription
Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2020/01/21/1nvdExploitMailing ListThird Party Advisory
- bugs.gentoo.org/692492nvdExploitIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.