CVE-2019-12875: Medium severity alpine linux vulnerability
Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --keys-dir option that causes acceptance of an untrusted signing key.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-12875?
CVE-2019-12875 is a vulnerability in Alpine Linux abuild through version 3.4.0 that allows an unprivileged member of the abuild group to add an untrusted package via a --keys-dir option that causes acceptance of an untrusted signing key.
What is the severity of CVE-2019-12875?
CVE-2019-12875 has a severity rating of 6.5 (medium).
How does CVE-2019-12875 affect Alpine Linux abuild?
CVE-2019-12875 affects Alpine Linux abuild versions up to and including 3.4.0.
How can CVE-2019-12875 be exploited?
CVE-2019-12875 can be exploited by an unprivileged member of the abuild group using the --keys-dir option to add an untrusted package with an untrusted signing key.
Are there any references about CVE-2019-12875?
Yes, you can find references about CVE-2019-12875 at the following URLs: [reference 1], [reference 2], [reference 3].