Fake Red Hat security update
Posted Oct 25, 2004 16:51 UTC (Mon) by
utidjian (subscriber, #444)
In reply to:
Fake Red Hat security update by JoeBuck
Parent article:
Fake Red Hat security update
"But an RPM that is not signed with a key that is already loaded into the rpm database will not install."
That is not quite true... at least not on any Red Hat or Fedora Core systems I have. It is true that 'yum update', 'apt-get update' and up2date will not, by default, install any unsigned or incorrectly signed packages.
However, a simple 'rpm -ivh someunsignedpackage.rpm' will just go right ahead and install it.
-DU-...etc...
(
Log in to post comments)