The signature verification functionality in the YaST Online Update (YOU) script handling relies on a gpg feature that is not intended for signature verification, which prevents YOU from detecting malicious scripts or code that do not pass the signature check when gpg 1.4.x is being used.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2006-02-23T20:00:00
Updated: 2006-04-18T09:00:00
Reserved: 2006-02-20T00:00:00
Link: CVE-2006-0803
JSON object: View
NVD Information
Status : Analyzed
Published: 2006-02-23T20:02:00.000
Modified: 2018-10-30T16:25:12.513
Link: CVE-2006-0803
JSON object: View
Redhat Information
No data.
CWE