This bulletin was written by Vigil@nce : http://vigilance.fr/offer
SYNTHESIS OF THE VULNERABILITY
An attacker can create a specially malformed rpm archive, with an
invalid signature, but which is not detected, so an attacker can
invite the administrator to install a malicious rpm.
Impacted products: Unix (platform)
Severity: 2/4
Creation date: 04/01/2013
DESCRIPTION OF THE VULNERABILITY
The rpm tool is used to install packages on the system.
The rpmpkgRead() function of the lib/package.c file checks the
signature of the package, before installing it. This function
calls parsePGPSig() to decode the signature. When the signature is
malformed, this function returns an error, but the integer storing
the error code is not set to RPMRC_FAIL. The rpmpkgRead() function
then uses the value RPMRC_OK, which means that the signature is
valid.
An attacker can therefore create a specially malformed rpm
archive, with an invalid signature, but which is not detected, so
an attacker can invite the administrator to install a malicious
rpm.
ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN
http://vigilance.fr/vulnerability/rpm-invalid-check-of-signature-12283






