First published: Fri Mar 19 2021(Updated: )
RPM does not require subkeys to have a valid binding signature. This could potentially result in a signature being wrongly trusted in the following (rather contrived) scenario: A malicious subkey (to which an attacker has the secret key) is added to a legitimate public key, via a process that rejects main keys but not subkeys and does not itself check binding signatures. The main key is exported and then imported into RPM.
Affected Software | Affected Version | How to fix |
---|---|---|
RPM Package Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-1941098 is considered a security vulnerability due to potential signature trust issues.
To mitigate REDHAT-BUG-1941098, ensure that RPM is updated to the latest version that addresses this issue.
REDHAT-BUG-1941098 affects the RPM Package Manager.
REDHAT-BUG-1941098 involves RPM not requiring subkeys to have a valid binding signature, which may lead to untrusted signatures being accepted.
The vulnerability, REDHAT-BUG-1941098, is managed by the RPM Package Manager's development team.