Safety vulnerability ID: 66717
The information on this page was manually curated by our Cybersecurity Intelligence Team.
In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Portage is not vulnerable.
Latest version: 3.0.67
Portage is the package management and distribution system for Gentoo
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application