CVE
- Id
- 6586
- CVE No.
- CVE-2002-2204
- Status
- Candidate
- Description
- The default --checksig setting in RPM Package Manager 4.0.4 checks that a package"s signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source.
- Phase
- Assigned (20051116)
- Votes
- None (candidate not yet proposed)
- Comments