Vulnerabilities > Gentoo > Portage > 2.0.50

DATE CVE VULNERABILITY TITLE RISK
2024-01-12 CVE-2016-20021 Improper Verification of Cryptographic Signature vulnerability in Gentoo Portage
In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification.
network
low complexity
gentoo CWE-347
critical
9.8
2004-12-31 CVE-2004-1901 Link Following vulnerability in Gentoo Linux and Portage
Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.
local
low complexity
gentoo CWE-59
5.5