The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an unparseable signature, which allows remote attackers to bypass RPM signature checks via a crafted package.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rpm | Rpm | 4.10.0 (including) | 4.10.0 (including) |
Rpm | Rpm | 4.10.1 (including) | 4.10.1 (including) |
Rpm | Ubuntu | hardy | * |
Rpm | Ubuntu | quantal | * |
Rpm | Ubuntu | upstream | * |