Skip to main content

Vendor archive

gentoo CVEs

Beta · best-effort

197 CVEs tagged to vendor gentoo37 Critical, 57 High, 72 Medium, 31 Low, 0 Unrated.

CVE-2024-12086

Published Jan 14, 2025

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a c…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2020-36770

Published Jan 15, 2024

pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root filesystem. This could be exploited by t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-20021

Published Jan 12, 2024

In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verificat…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-28424

Published Mar 20, 2023

Soko if the code that powers packages.gentoo.org. Prior to version 1.0.2, the two package search handlers, `Search` and `SearchFeed`, implemented in `pkg/app/handler/packages/sear…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-26033

Published Feb 25, 2023

Gentoo soko is the code that powers packages.gentoo.org. Versions prior to 1.0.1 are vulnerable to SQL Injection, leading to a Denial of Service. If the user selects (in user pref…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20384

Published Jan 21, 2020

Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to the nagios user account, because…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18285

Published Jun 4, 2018

The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain read and write access to arbitra…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18284

Published Jun 4, 2018

The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by lev…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18226

Published Mar 12, 2018

The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill arbitrary processes by leveragi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18225

Published Mar 12, 2018

The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which migh…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14730

Published Sep 25, 2017

The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14484

Published Sep 15, 2017

The Gentoo sci-mathematics/gimps package before 28.10-r1 for Great Internet Mersenne Prime Search (GIMPS) allows local users to gain privileges by creating a hard link under /var/…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14483

Published Sep 15, 2017

flower.initd in the Gentoo dev-python/flower package before 0.9.1-r1 for Celery Flower sets PID file ownership to a non-root account, which might allow local users to kill arbitra…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2778

Published Jun 27, 2017

Ebuild in Gentoo may change directory and file permissions depending on the order of installed packages, which allows local users to read or write to restricted directories or exe…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9622

Published Jan 21, 2015

Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execute arbitrary code via the URL…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2100

Published Sep 29, 2014

The urlopen function in pym/portage/util/_urlopen.py in Gentoo Portage 2.1.12, when using HTTPS, does not verify X.509 certificates from SSL servers, which allows man-in-the-middl…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-4223

Published May 23, 2014

The Gentoo Nullmailer package before 1.11-r2 uses world-readable permissions for /etc/nullmailer/remotes, which allows local users to obtain SMTP authentication credentials by rea…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 197 CVEsPage 1 of 8