PT-2003-1060 · Red Hat · Up2Date+1

Barry Nathan

·

Published

2003-08-08

·

Updated

2017-10-11

·

CVE-2003-0546

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions up2date versions 3.0.7 through 3.1.23
Description The issue is related to the improper verification of RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network if that network is compromised. This could lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation of this issue can be done remotely.
Recommendations For up2date versions 3.0.7 through 3.1.23, ensure that RPM GPG signatures are properly verified to prevent the installation of unsigned packages. As a temporary workaround, consider restricting access to the Red Hat Network until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07912
BDU:2015-07913
BDU:2015-07914
BDU:2015-07915
CVE-2003-0546

Affected Products

Rpm
Up2Date