LWN.net Logo

Fake Red Hat security update

Fake Red Hat security update

Posted Oct 25, 2004 16:51 UTC (Mon) by utidjian (subscriber, #444)
In reply to: Fake Red Hat security update by JoeBuck
Parent article: Fake Red Hat security update

"But an RPM that is not signed with a key that is already loaded into the rpm database will not install."

That is not quite true... at least not on any Red Hat or Fedora Core systems I have. It is true that 'yum update', 'apt-get update' and up2date will not, by default, install any unsigned or incorrectly signed packages. However, a simple 'rpm -ivh someunsignedpackage.rpm' will just go right ahead and install it. -DU-...etc...


(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds