The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source.
Loading...
Loading...
The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source.
December 31, 2002
April 16, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2002-2204
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.