CVE-2002-2204

The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:redhat_package_manager:4.0.2-71:*:*:*:*:*:*:*
cpe:2.3:a:redhat:redhat_package_manager:4.0.2-72:*:*:*:*:*:*:*
cpe:2.3:a:redhat:redhat_package_manager:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:redhat_package_manager:4.0.4:*:*:*:*:*:*:*

History

20 Nov 2024, 23:43

Type Values Removed Values Added
References () http://lists.netsys.com/pipermail/full-disclosure/2002-August/001167.html - () http://lists.netsys.com/pipermail/full-disclosure/2002-August/001167.html -
References () http://www.iss.net/security_center/static/10011.php - () http://www.iss.net/security_center/static/10011.php -
References () http://www.securityfocus.com/bid/5594 - Patch () http://www.securityfocus.com/bid/5594 - Patch

Information

Published : 2002-12-31 05:00

Updated : 2025-04-03 01:03


NVD link : CVE-2002-2204

Mitre link : CVE-2002-2204

CVE.ORG link : CVE-2002-2204


JSON object : View

Products Affected

redhat

  • redhat_package_manager