CVE-2016-20021: Critical severity gentoo portage vulnerability
In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Portage is not vulnerable.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-20021?
CVE-2016-20021 has a severity rating that indicates a potential risk due to the lack of PGP validation in Gentoo Portage.
How do I fix CVE-2016-20021?
To fix CVE-2016-20021, upgrade your Gentoo Portage installation to version 3.0.47 or later.
What systems are affected by CVE-2016-20021?
CVE-2016-20021 affects Gentoo Portage versions prior to 3.0.47 when using the emerge-webrsync command.
Is CVE-2016-20021 a critical vulnerability?
CVE-2016-20021 is not classified as a critical vulnerability, but it does pose risks if not addressed.
What does CVE-2016-20021 involve?
CVE-2016-20021 involves a missing PGP validation in Gentoo Portage's emerge-webrsync, which could lead to executing unverified code.