Vulnerabilities > Gentoo

DATE CVE VULNERABILITY TITLE RISK
2024-01-15 CVE-2020-36770 Unspecified vulnerability in Gentoo Ebuild for Slurm
pkg_postinst in the Gentoo ebuild for Slurm through 22.05.3 unnecessarily calls chown to assign root's ownership on files in the live root filesystem.
network
low complexity
gentoo
critical
9.8
2024-01-12 CVE-2016-20021 Improper Verification of Cryptographic Signature vulnerability in Gentoo Portage
In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification.
network
low complexity
gentoo CWE-347
critical
9.8
2023-12-18 CVE-2023-48795 Improper Validation of Integrity Check Value vulnerability in multiple products
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack.
5.9
2023-03-20 CVE-2023-28424 SQL Injection vulnerability in Gentoo Soko
Soko if the code that powers packages.gentoo.org.
network
low complexity
gentoo CWE-89
critical
9.8
2023-02-25 CVE-2023-26033 SQL Injection vulnerability in Gentoo Soko
Gentoo soko is the code that powers packages.gentoo.org.
network
low complexity
gentoo CWE-89
critical
9.1
2020-01-21 CVE-2019-20384 Improper Preservation of Permissions vulnerability in Gentoo Portage
Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to the nagios user account, because this directory is writable in between a call to emake and a call to fowners.
local
low complexity
gentoo CWE-281
2.1
2018-06-04 CVE-2017-18285 Incorrect Permission Assignment for Critical Resource vulnerability in Burp Project Burp
The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might allow local users to obtain read and write access to arbitrary files by leveraging access to a certain account for a burp-server.conf change.
local
low complexity
burp-project gentoo CWE-732
3.6
2018-06-04 CVE-2017-18284 Incorrect Permission Assignment for Critical Resource vulnerability in Burp Project Burp
The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script sends a SIGKILL.
local
low complexity
burp-project gentoo CWE-732
3.6
2018-03-12 CVE-2017-18226 Incorrect Permission Assignment for Critical Resource vulnerability in Jabberd2
The Gentoo net-im/jabberd2 package through 2.6.1 sets the ownership of /var/run/jabber to the jabber account, which might allow local users to kill arbitrary processes by leveraging access to this account for PID file modification before a root script executes a "kill -TERM `cat /var/run/jabber/filename.pid`" command.
local
low complexity
jabberd2 gentoo CWE-732
2.1
2018-03-12 CVE-2017-18225 Incorrect Permission Assignment for Critical Resource vulnerability in Jabberd2
The Gentoo net-im/jabberd2 package through 2.6.1 installs jabberd, jabberd2-c2s, jabberd2-router, jabberd2-s2s, and jabberd2-sm in /usr/bin owned by the jabber account, which might allow local users to gain privileges by leveraging access to this account and then waiting for root to execute one of these programs.
local
low complexity
jabberd2 gentoo CWE-732
4.6