Security Advisory

CVE-2016-20021

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-01-12 00:00:00
Last updated 2025-06-03 14:07:01
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Portage is not vulnerable.