First published: Tue Jun 18 2019(Updated: )
Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --keys-dir option that causes acceptance of an untrusted signing key.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Alpine Linux | <=3.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12875 is a vulnerability in Alpine Linux abuild through version 3.4.0 that allows an unprivileged member of the abuild group to add an untrusted package via a --keys-dir option that causes acceptance of an untrusted signing key.
CVE-2019-12875 has a severity rating of 6.5 (medium).
CVE-2019-12875 affects Alpine Linux abuild versions up to and including 3.4.0.
CVE-2019-12875 can be exploited by an unprivileged member of the abuild group using the --keys-dir option to add an untrusted package with an untrusted signing key.
Yes, you can find references about CVE-2019-12875 at the following URLs: [reference 1], [reference 2], [reference 3].