Lucene search

K
githubGitHub Advisory DatabaseGHSA-PW5X-X5JW-CCMH
HistoryJan 12, 2024 - 3:30 a.m.

Gentoo Portage missing PGP validation of executed code

2024-01-1203:30:49
CWE-347
GitHub Advisory Database
github.com
2
gentoo
portage
pgp
validation
code
emerge-webrsync
signature
verification
software

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.8

Confidence

High

In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification.

Affected configurations

Vulners
Node
gentooportageRange0
OR
gentooportageRange<3.0.47
VendorProductVersionCPE
gentooportage*cpe:2.3:a:gentoo:portage:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.8

Confidence

High

Related for GHSA-PW5X-X5JW-CCMH