CVE-2002-2204

The MITRE CVE dictionary describes this issue as:

The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source.

Find out more about CVE-2002-2204 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

We do not believe this is a security vulnerability. This is the documented and expected behaviour of rpm.

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.