Description
up2date 3.0.7 and 3.1.23 does not properly verify RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network, if that network is compromised.
Product(s):
- Red Hat up2date 3.0.7-1 on i386
- Red Hat up2date 3.0.7-1 GNOME on i386
- Red Hat up2date 3.1.23-1 on i386
- Red Hat up2date 3.1.23-1 GNOME on i386
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-2003-0546, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2003-0546 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.