Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2002-2204

Опубликовано: 31 дек. 2002
Источник: debian

Описание

The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source.

Примечания

  • verified with rpm 4.4.1, but this can hardly affect debian at

  • all since it requires rpm be configured to trust some key,

  • which in debian requires a manual and non-documented

  • initialization of the rpm database which is not configured in

  • the package

Связанные уязвимости

nvd
почти 23 года назад

The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source.

github
больше 3 лет назад

The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source.