Red Hat Linux Up2Date GPG Signature Validation Vulnerability
BID:8372
Info
Red Hat Linux Up2Date GPG Signature Validation Vulnerability
| Bugtraq ID: | 8372 |
| Class: | Design Error |
| CVE: |
CVE-2003-0546 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 08 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Discovery of this vulnerability has been credited to Barry Nathan. |
| Vulnerable: |
Redhat up2date-gnome-3.1.23-1.i386.rpm Redhat up2date-gnome-3.0.7-1.i386.rpm Redhat up2date-3.1.23-1.i386.rpm Redhat up2date-3.0.7-1.i386.rpm |
| Not Vulnerable: | |
Discussion
Red Hat Linux Up2Date GPG Signature Validation Vulnerability
It has been reported that the up2date tool does not sufficiently validate GPG signatures on rpm packages downloaded from the Red Hat Network. This issue may provide for the installation of a package, which do not posses a GPG signature.
It has been reported that the up2date tool does not sufficiently validate GPG signatures on rpm packages downloaded from the Red Hat Network. This issue may provide for the installation of a package, which do not posses a GPG signature.
Exploit / POC
Red Hat Linux Up2Date GPG Signature Validation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Red Hat Linux Up2Date GPG Signature Validation Vulnerability
Solution:
Red Hat has released an advisory (RHSA-2003:255-01) to address this issue, see referenced advisory for further details regarding applying fixes. Fixes are linked below.
Solution:
Red Hat has released an advisory (RHSA-2003:255-01) to address this issue, see referenced advisory for further details regarding applying fixes. Fixes are linked below.
References
Red Hat Linux Up2Date GPG Signature Validation Vulnerability
References:
References: