Back

HIGH

The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source

Published Nov 16, 2005

Description

The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source.

Affected products

Remediation

Red Hat statement

We do not believe this is a security vulnerability. This is the documented and expected behaviour of rpm.

Metrics

Weaknesses (0)

No CWE recorded.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 16, 2005
Updated Sep 17, 2024
Reserved Nov 16, 2005
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a