RPM CVE-2012-6088 Signature Verification Security Bypass Vulnerability
BID:57138
Info
RPM CVE-2012-6088 Signature Verification Security Bypass Vulnerability
| Bugtraq ID: | 57138 |
| Class: | Design Error |
| CVE: |
CVE-2012-6088 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 03 2013 12:00AM |
| Updated: | Jan 17 2013 05:10PM |
| Credit: | Reported by vendor. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
RPM CVE-2012-6088 Signature Verification Security Bypass Vulnerability
RPM is prone to a security-bypass vulnerability.
An attacker may exploit this issue to bypass signature verification and cause the application to accept unsigned packages. Successful attacks may allow the attacker to execute arbitrary code on a vulnerable computer.
RPM is prone to a security-bypass vulnerability.
An attacker may exploit this issue to bypass signature verification and cause the application to accept unsigned packages. Successful attacks may allow the attacker to execute arbitrary code on a vulnerable computer.
Exploit / POC
RPM CVE-2012-6088 Signature Verification Security Bypass Vulnerability
An attacker can exploit this issue using readily available utilities.
An attacker can exploit this issue using readily available utilities.
Solution / Fix
RPM CVE-2012-6088 Signature Verification Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
RPM CVE-2012-6088 Signature Verification Security Bypass Vulnerability
References:
References:
- RPM Homepage (RPM)