CVE-2014-0022
26.01.2014, 16:58
The installUpdates function in yum-cron/yum-cron.py in yum 3.4.3 and earlier does not properly check the return value of the sigCheckPkg function, which allows remote attackers to bypass the RMP package signing restriction via an unsigned package.Enginsight
| Vendor | Product | Version |
|---|---|---|
| baseurl | yum | 𝑥 ≤ 3.4.3 |
| baseurl | yum | 3.4.0 |
| baseurl | yum | 3.4.1 |
| baseurl | yum | 3.4.2 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| yum |
|
Common Weakness Enumeration
References