Skip to main content

Vendor/product archive

gentoo / portage CVEs

Beta · best-effort

7 CVEs tagged to gentoo / portage2 Critical, 1 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2016-20021

Published Jan 12, 2024

In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verificat…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-20384

Published Jan 21, 2020

Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to the nagios user account, because…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2778

Published Jun 27, 2017

Ebuild in Gentoo may change directory and file permissions depending on the order of installed packages, which allows local users to read or write to restricted directories or exe…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2100

Published Sep 29, 2014

The urlopen function in pym/portage/util/_urlopen.py in Gentoo Portage 2.1.12, when using HTTPS, does not verify X.509 certificates from SSL servers, which allows man-in-the-middl…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4394

Published Oct 10, 2008

Multiple untrusted search path vulnerabilities in Portage before 2.1.4.5 include the current working directory in the Python search path, which allows local users to execute arbit…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6249

Published Dec 15, 2007

etc-update in Portage before 2.1.3.11 on Gentoo Linux relies on the umask to set permissions for the merge file, often resulting in permissions weaker than those of the original f…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1