Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The installUpdates function in yum-cron/yum-cron.py in yum 3.4.3 and earlier does not properly check the return value of the sigCheckPkg function, which allows remote attackers to bypass the RMP package signing restriction via an unsigned package.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Yum 输入验证错误漏洞
Vulnerability Description
Yum是美国杜克大学(Duke University)团队开发的一款基于RPM包管理的Shell字符前端软件包管理器,它支持从指定的服务器自动下载RPM包并且安装,以及处理依赖性关系。 Yum 3.4.3版本及之前版本存在输入验证错误漏洞,该漏洞源于程序没有检查sigCheckPkg函数的返回值。远程攻击者利用该漏洞绕过RMP数据包签名限制。
CVSS Information
N/A
Vulnerability Type
N/A