CVE-2002-2204
Description
From CVE.org
The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source.
Statement
We do not believe this is a security vulnerability. This is the documented and expected behaviour of rpm.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.