Release date:
Updated on:
Affected Systems:
Baseurl yum 3.4.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65119
CVE (CAN) ID: CVE-2014-0022
Yum is a package manager under Fedora and RedHat linux.
In Yum 3.4.3 and earlier versions, the installUpdates function of yum-cron/yum-cron.py does not properly check the return value of the sigCheckPkg function, which allows remote attackers to pass unsigned software packages, this vulnerability bypasses the RMP Software Package signature restriction.
<* Source: Gabriel VLASIU
Link: http://secunia.com/advisories/56637
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Baseurl
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://yum.baseurl.org
Http://yum.baseurl.org/gitweb? P = yum. git; a = commitdiff; h = 9df69e5794