PT-2007-1043 · Debian · Reprepro

Bernhard R. Link

·

Publicado

2007-09-06

·

Atualizado

2009-02-05

·

CVE-2007-4739

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: reprepro versions 1.3.0 through 2.2.3
Description: The issue is related to the improper verification of signatures when updating repositories, allowing remote attackers to construct and distribute an ostensibly valid Release.gpg file by signing it with an unknown key. This is related to the update command. Multiple vulnerabilities in the reprepro package of the Debian GNU/Linux operating system can lead to a violation of the integrity of protected information and can be exploited remotely.
Recommendations: For versions 1.3.0 through 2.2.3, update to a version that properly verifies signatures when updating repositories to prevent remote attackers from constructing and distributing an ostensibly valid Release.gpg file. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03508
CVE-2007-4739
DSA-1394-1

Produtos afetados

Reprepro