Back
CVE-2005-4442
Untrusted search path vulnerability in OpenLDAP before 2.2.28-r3 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.
Published: Dec 21, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (82)
| Vendor | Product | Version |
|---|---|---|
| openldap | openldap | * |
| openldap | openldap | 2.0.0 |
| openldap | openldap | 2.0.1 |
| openldap | openldap | 2.0.2 |
| openldap | openldap | 2.0.3 |
| openldap | openldap | 2.0.4 |
| openldap | openldap | 2.0.5 |
| openldap | openldap | 2.0.6 |
| openldap | openldap | 2.0.7 |
| openldap | openldap | 2.0.8 |
| openldap | openldap | 2.0.9 |
| openldap | openldap | 2.0.10 |
| openldap | openldap | 2.0.11 |
| openldap | openldap | 2.0.12 |
| openldap | openldap | 2.0.13 |
| openldap | openldap | 2.0.14 |
| openldap | openldap | 2.0.15 |
| openldap | openldap | 2.0.16 |
| openldap | openldap | 2.0.17 |
| openldap | openldap | 2.0.18 |
…and 62 more
GitHub Security Advisory GHSA-4rj4-mjp8-mcgg
Untrusted search path vulnerability in OpenLDAP before 2.2.28-r3 on Gentoo Linux allows local...
References (6)
- http://secunia.com/advisories/18040/ Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200512-07.xml Patch
- http://www.securityfocus.com/bid/15120 Patch
- http://secunia.com/advisories/18040/ Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200512-07.xml Patch
- http://www.securityfocus.com/bid/15120 Patch
Risk Scores
CVSS Score
7.2 / 10
EPSS Score
0.46%
Top 61% most likely to be exploited
Threat Score
28.9 / 100
Data Sources
NVD
EPSS
GitHub