|
|
| |
|
| |
reprepro: authentication bypass
| Package(s): | reprepro |
CVE #(s): | CVE-2007-4739
|
| Created: | October 24, 2007 |
Updated: | October 24, 2007 |
| Description: |
From the Debian advisory:
It was discovered that reprepro, a tool to create a repository of Debian
packages, when updating from a remote site only checks for the validity of
known signatures, and thus does not reject packages with only unknown
signatures. This allows an attacker to bypass this authentication
mechanism. |
| Alerts: |
|
( Log in to post comments)
|
|
|