PT-2013-1881 · Rpm · Rpm
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
RPM versions 4.10.x through 4.10.1
Description
The issue concerns the
rpmpkgRead function in lib/package.c, which fails to return an error code when encountering an "unparseable signature" in certain situations. This allows remote attackers to bypass RPM signature checks by crafting a malicious package.Recommendations
For RPM versions 4.10.x through 4.10.1, update to version 4.10.2 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Rpm