CVE-2016-20021
CRITICALGentoo Portage <3.0.47 - Info Disclosure
Title source: llmDescription
In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Portage is not vulnerable.
Scores
CVSS v3
9.8
EPSS
0.0004
EPSS Percentile
11.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-347
Status
published
Affected Products (2)
gentoo/portage
< 3.0.47
pypi/portage
< 3.0.47PyPI
Timeline
Published
Jan 12, 2024
Tracked Since
Feb 18, 2026