CVE-2017-14484: Gentoo Sci-Mathematics-Gimps

High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Gentoo sci-mathematics/gimps package before 28.10-r1 for Great Internet Mersenne Prime Search (GIMPS) allows local users to gain privileges by creating a hard link under /var/lib/gimps, because an unsafe "chown -R" command is executed.

Affected products

  • Gentoo Sci-Mathematics-Gimps: version 28.10 only

Published 2017-09-15. Last modified 2026-06-17.