PT-2003-1060 · Red Hat · Up2Date+1
Barry Nathan
·
Published
2003-08-08
·
Updated
2017-10-11
·
CVE-2003-0546
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
up2date versions 3.0.7 through 3.1.23
Description
The issue is related to the improper verification of RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network if that network is compromised. This could lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be done remotely.
Recommendations
For up2date versions 3.0.7 through 3.1.23, ensure that RPM GPG signatures are properly verified to prevent the installation of unsigned packages. As a temporary workaround, consider restricting access to the Red Hat Network until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rpm
Up2Date