Back

MEDIUM

PackageKit: installs unsigned RPM packages as though they were signed

Published Nov 27, 2019

Description

PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and execution of arbitrary code.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 27, 2019
Updated Aug 6, 2024
Reserved Jun 15, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Jul 1, 2011