Security readout for executives and security teams
Plain-English summary
This CVE affects Gentoo’s GIMPS package before 28.10-r1. A local user could abuse unsafe ownership changes under /var/lib/gimps to gain higher privileges. It is not a remote internet-facing issue based on the provided sources, but it matters on shared Gentoo systems or hosts where untrusted users can log in.
Executive priority
Prioritize remediation for shared Gentoo servers and any systems with untrusted local users. For single-user or isolated hosts, treat this as routine hardening unless local account compromise is a credible scenario.
Technical view
Gentoo sci-mathematics/gimps before 28.10-r1 executes an unsafe recursive chown operation. A local user can create a hard link under /var/lib/gimps, causing ownership changes to affect unintended files and enabling privilege escalation. No CVSS, CWE, or detailed affected CPE data is provided in the bundle.
Likely exposure
Exposure is limited to Gentoo systems with sci-mathematics/gimps installed at versions before 28.10-r1, especially where non-admin users have local access. The bundle does not support claims about other distributions, upstream GIMPS packages, or remotely exploitable exposure.
Exploitation context
The CVE describes local privilege escalation through filesystem hard links and unsafe recursive ownership changes. The source bundle does not indicate active exploitation, public exploit availability, or inclusion in CISA KEV.
Researcher notes
The public bundle is sparse: it names the vulnerable Gentoo package, fixed version boundary, local-user impact, /var/lib/gimps hard-link condition, and unsafe chown -R behavior. It does not provide CVSS scoring, CWE mapping, exploit status, or broader product impact.
Mitigation direction
- Upgrade Gentoo sci-mathematics/gimps to 28.10-r1 or later.
- Remove the package from systems where GIMPS is not required.
- Restrict local shell access to affected hosts until remediated.
- Review the linked Gentoo bug for vendor-specific remediation guidance.
Validation and detection
- Inventory Gentoo hosts for installed sci-mathematics/gimps packages.
- Confirm any installed version is 28.10-r1 or later.
- Check whether /var/lib/gimps exists on affected systems.
- Identify hosts where untrusted users have local access.
- Review package manager logs to confirm remediation timing.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2017-14484 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://bugs.gentoo.org/show_bug.cgi?id=603408CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
