Vigil@nce - rpm: invalid check of signature

This bulletin was written by Vigil@nce : http://vigilance.fr/offer

SYNTHESIS OF THE VULNERABILITY

An attacker can create a specially malformed rpm archive, with an
invalid signature, but which is not detected, so an attacker can
invite the administrator to install a malicious rpm.

Impacted products: Unix (platform)

Severity: 2/4

Creation date: 04/01/2013

DESCRIPTION OF THE VULNERABILITY

The rpm tool is used to install packages on the system.

The rpmpkgRead() function of the lib/package.c file checks the
signature of the package, before installing it. This function
calls parsePGPSig() to decode the signature. When the signature is
malformed, this function returns an error, but the integer storing
the error code is not set to RPMRC_FAIL. The rpmpkgRead() function
then uses the value RPMRC_OK, which means that the signature is
valid.

An attacker can therefore create a specially malformed rpm
archive, with an invalid signature, but which is not detected, so
an attacker can invite the administrator to install a malicious
rpm.

ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN

http://vigilance.fr/vulnerability/rpm-invalid-check-of-signature-12283

Articles similaires

Security Vulnerability

7 October 2026

Vigilance.fr - Apple macOS: information disclosure via Screen Sharing, analyzed on 07/08/2026

An attacker can bypass access restrictions to data of Apple macOS, via Screen Sharing, in order (…)

Security Vulnerability

7 October 2026

Vigilance.fr - Linux kernel: multiple vulnerabilities dated 07/08/2026

An attacker can use several vulnerabilities of the Linux kernel, dated 07/08/2026.

Security Vulnerability

7 October 2026

Vigilance.fr - Microsoft Teams: three vulnerabilities dated 07/08/2026

An attacker can use several vulnerabilities of Microsoft Teams, dated 07/08/2026.