Back

CVE-2005-4442

Untrusted search path vulnerability in OpenLDAP before 2.2.28-r3 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.

Published: Dec 21, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (82)

Vendor Product Version
openldap openldap *
openldap openldap 2.0.0
openldap openldap 2.0.1
openldap openldap 2.0.2
openldap openldap 2.0.3
openldap openldap 2.0.4
openldap openldap 2.0.5
openldap openldap 2.0.6
openldap openldap 2.0.7
openldap openldap 2.0.8
openldap openldap 2.0.9
openldap openldap 2.0.10
openldap openldap 2.0.11
openldap openldap 2.0.12
openldap openldap 2.0.13
openldap openldap 2.0.14
openldap openldap 2.0.15
openldap openldap 2.0.16
openldap openldap 2.0.17
openldap openldap 2.0.18

…and 62 more

GitHub Security Advisory GHSA-4rj4-mjp8-mcgg

Untrusted search path vulnerability in OpenLDAP before 2.2.28-r3 on Gentoo Linux allows local...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 0.46%

Top 61% most likely to be exploited

Threat Score 28.9 / 100

Data Sources

NVD EPSS GitHub