LWN.net Logo

reprepro: authentication bypass

Package(s):reprepro CVE #(s):CVE-2007-4739
Created:October 24, 2007 Updated:October 24, 2007
Description: From the Debian advisory:

It was discovered that reprepro, a tool to create a repository of Debian packages, when updating from a remote site only checks for the validity of known signatures, and thus does not reject packages with only unknown signatures. This allows an attacker to bypass this authentication mechanism.

Alerts:
Debian DSA-1394-1 2007-10-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds