PackageKit Signature Verification Security Bypass Vulnerability
BID:48557
CVE-2011-2515 |Info
PackageKit Signature Verification Security Bypass Vulnerability
| Bugtraq ID: | 48557 |
| Class: | Design Error |
| CVE: |
CVE-2011-2515 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 04 2011 12:00AM |
| Updated: | Apr 13 2015 09:59PM |
| Credit: | Peter Robinson |
| Vulnerable: |
Packagekit Project Packagekit 0 |
| Not Vulnerable: | |
Discussion
PackageKit Signature Verification Security Bypass Vulnerability
PackageKit is prone to a signature-verification security-bypass vulnerability because of an error that occurs when verifying the GPG signature of a package.
An attacker may exploit this issue to lead a user into a false sense of security and cause the application to accept unsigned packages. Successful attacks may allow the attacker to execute arbitrary code on a vulnerable computer.
PackageKit is prone to a signature-verification security-bypass vulnerability because of an error that occurs when verifying the GPG signature of a package.
An attacker may exploit this issue to lead a user into a false sense of security and cause the application to accept unsigned packages. Successful attacks may allow the attacker to execute arbitrary code on a vulnerable computer.
Exploit / POC
PackageKit Signature Verification Security Bypass Vulnerability
An attacker can exploit this issue using readily available utilities.
An attacker can exploit this issue using readily available utilities.
Solution / Fix
PackageKit Signature Verification Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
PackageKit Signature Verification Security Bypass Vulnerability
References:
References: