Back

MEDIUM

rpm: Signature checking function returned success on (possibly malicious ) rpm packages

Published Jan 18, 2013

Description

The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an "unparseable signature," which allows remote attackers to bypass RPM signature checks via a crafted package.

Affected products

Remediation

Red Hat statement

Not vulnerable. This issue did not affect the versions of rpm as shipped with Red Hat Enterprise Linux 5 and 6 as they did not include the upstream commit e8bc3ff5d780f4ee6656c24464402723e5fb04f4 that introduced this issue.

Metrics

Weaknesses (2)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 18, 2013
Updated Aug 6, 2024
Reserved Dec 6, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Feb 13, 2023