Search/CVE-2007-0476
CVE

CVE-2007-0476

The gencert.sh script, when installing OpenLDAP before 2.1.30-r10, 2.2.x before 2.2.28-r7, and 2.3.x before 2.3.30-r2 as an ebuild in Gentoo Linux, does not create temporary directories in /tmp securely during emerge, which allows local users to overwrite arbitrary files via a symlink attack.

CVSS v3.1
EPSS
0.36%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Aug 24, 2026
0.02pp
0.35% → 0.36% over 2 tracked changes
Connections
1 relationships
Timeline
disclosure → media coverage
Jan 25, 2007
Disclosure — published as a CVE record. · last revised by NVD Apr 23, 2026