CVE detail
CVE-2008-4394 — CVE-2008-4394
Published 2008-10-10 · Modified 2026-06-16 · Vendor gentoo · Product portage · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0034
EPSS probability
exploitation probability, 30d
26.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Multiple untrusted search path vulnerabilities in Portage before 2.1.4.5 include the current working directory in the Python search path, which allows local users to execute arbitrary code via a modified Python module that is loaded by the (1) ys-apps/portage, (2) net-mail/fetchmail, (3) app-editors/leo ebuilds, and other ebuilds.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References