pinentry on Gentoo Linux Installation Permission Weakness
Local Access Required
Loss of Confidentiality,
Loss of Integrity
pinentry on Gentoo Linux contains a flaw that may allow a malicious user to access files with unauthorised privileges. The issue is present because pinentry is installed as SGID root. This may result in a loss of confidentiality and/or integrity.
Gentoo users need to upgrade to version 0.7.2-r2 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.