LWN.net Logo

rpm: incorrect signature checking

Package(s):rpm CVE #(s):CVE-2012-6088
Created:January 17, 2013 Updated:January 23, 2013
Description:

From the Ubuntu advisory:

It was discovered that RPM incorrectly handled signature checking. An attacker could create a specially-crafted rpm with an invalid signature which could pass the signature validation check.

Alerts:
Ubuntu USN-1694-1 2013-01-17

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds