The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an unparseable signature, which allows remote attackers to bypass RPM signature checks via a crafted package.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Rpm | Rpm | 4.10.0 (including) | 4.10.0 (including) |
| Rpm | Rpm | 4.10.1 (including) | 4.10.1 (including) |
| Rpm | Ubuntu | hardy | * |
| Rpm | Ubuntu | quantal | * |
| Rpm | Ubuntu | upstream | * |