CVE-2019-20384: Gentoo Portage

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directory by leveraging access to the nagios user account, because this directory is writable in between a call to emake and a call to fowners.

Affected products

  • Gentoo Portage: up to and including 2.3.84

Published 2020-01-21. Last modified 2026-06-17.