Back

CVE-2005-4280

Untrusted search path vulnerability in CMake before 2.2.0-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.

Published: Dec 16, 2005 Modified: Jun 16, 2026

CVSS Metrics

GitHub Security Advisory GHSA-2mgc-grxm-67g2

Untrusted search path vulnerability in CMake before 2.2.0-r1 on Gentoo Linux allows local users...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 0.52%

Top 58% most likely to be exploited

Threat Score 29 / 100

Data Sources

NVD EPSS GitHub