|
|
Subscribe / Log in / New account

portage: certificate verification botch

Package(s):portage CVE #(s):CVE-2013-2100
Created:July 10, 2015 Updated:July 15, 2015
Description: From the Gentoo advisory:

Portage does not verify X.509 SSL certificate properly if HTTPS is used.

A remote attacker can spoof servers and modify binary package lists via specially crafted certificate.

Alerts:
Gentoo 201507-16 portage 2015-07-10

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds