LiveActive security incident?Get immediate response
CVE Record

CVE-2017-14484: The Gentoo sci-mathematics/gimps package before 28.10-r1 for Great Internet Mersenne Prime Search (GIMPS) a...

The Gentoo sci-mathematics/gimps package before 28.10-r1 for Great Internet Mersenne Prime Search (GIMPS) allows local users to gain privileges by creating a hard link under /var/lib/gimps, because an unsafe "chown -R" command is executed.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This CVE affects Gentoo’s GIMPS package before 28.10-r1. A local user could abuse unsafe ownership changes under /var/lib/gimps to gain higher privileges. It is not a remote internet-facing issue based on the provided sources, but it matters on shared Gentoo systems or hosts where untrusted users can log in.

Executive priority

Prioritize remediation for shared Gentoo servers and any systems with untrusted local users. For single-user or isolated hosts, treat this as routine hardening unless local account compromise is a credible scenario.

Technical view

Gentoo sci-mathematics/gimps before 28.10-r1 executes an unsafe recursive chown operation. A local user can create a hard link under /var/lib/gimps, causing ownership changes to affect unintended files and enabling privilege escalation. No CVSS, CWE, or detailed affected CPE data is provided in the bundle.

Likely exposure

Exposure is limited to Gentoo systems with sci-mathematics/gimps installed at versions before 28.10-r1, especially where non-admin users have local access. The bundle does not support claims about other distributions, upstream GIMPS packages, or remotely exploitable exposure.

Exploitation context

The CVE describes local privilege escalation through filesystem hard links and unsafe recursive ownership changes. The source bundle does not indicate active exploitation, public exploit availability, or inclusion in CISA KEV.

Researcher notes

The public bundle is sparse: it names the vulnerable Gentoo package, fixed version boundary, local-user impact, /var/lib/gimps hard-link condition, and unsafe chown -R behavior. It does not provide CVSS scoring, CWE mapping, exploit status, or broader product impact.

Mitigation direction

  • Upgrade Gentoo sci-mathematics/gimps to 28.10-r1 or later.
  • Remove the package from systems where GIMPS is not required.
  • Restrict local shell access to affected hosts until remediated.
  • Review the linked Gentoo bug for vendor-specific remediation guidance.

Validation and detection

  • Inventory Gentoo hosts for installed sci-mathematics/gimps packages.
  • Confirm any installed version is 28.10-r1 or later.
  • Check whether /var/lib/gimps exists on affected systems.
  • Identify hosts where untrusted users have local access.
  • Review package manager logs to confirm remediation timing.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2017-14484 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.