The default –checksig setting in RPM Package Manager 4.0.4 checks that a packages signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Redhat_package_manager | Redhat | 4.0.2-71 (including) | 4.0.2-71 (including) |
| Redhat_package_manager | Redhat | 4.0.2-72 (including) | 4.0.2-72 (including) |
| Redhat_package_manager | Redhat | 4.0.3 (including) | 4.0.3 (including) |
| Redhat_package_manager | Redhat | 4.0.4 (including) | 4.0.4 (including) |