From 230d731718c558194c0f0f4db0db15fa3d590f43 Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Sun, 22 Sep 2024 05:36:27 +0000 Subject: [ GLSA 202409-01 ] Portage: Unverified PGP Signatures Bug: https://bugs.gentoo.org/905356 Signed-off-by: GLSAMaker Signed-off-by: Hans de Graaff --- glsa-202409-01.xml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 glsa-202409-01.xml diff --git a/glsa-202409-01.xml b/glsa-202409-01.xml new file mode 100644 index 00000000..34f747f5 --- /dev/null +++ b/glsa-202409-01.xml @@ -0,0 +1,42 @@ + + + + Portage: Unverified PGP Signatures + A vulnerability has been discovered in Portage, where PGP signatures would not be verified. + portage + 2024-09-22 + 2024-09-22 + 905356 + local + + + 3.0.47 + 3.0.47 + + + +

Portage is the default Gentoo package management system.

+
+ +

Multiple vulnerabilities have been discovered in Portage. Please review the CVE identifiers referenced below for details.

+
+ +

When using the webrsync mechanism to sync the tree the PGP signatures that protect the integrity of the data in the tree would not be verified. This would allow a man-in-the-middle attack to inject arbitrary content into the tree.

+
+ +

There is no known workaround at this time.

+
+ +

All Portage users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-apps/portage-3.0.47" + +
+ + CVE-2016-20021 + + graaff + graaff +
\ No newline at end of file -- cgit v1.2.3-65-gdbad