Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Red Hat Linux 8.0 RHSA-2003:255-01 Moderate GPG Signature Exploit

red hat
Calendar Grey August 8, 2003
Dist Redhat Esm H88
Investigate the security risks of Red Hat's up2date tool related to GPG signature validation issues. Discover strategies to enhance system security and mitigate these vulnerabilities
up2date versions 3.0.7 and 3.1.23 incorrectly check RPM GPG signatures

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs.

Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate RPMs being upgraded on your system.

5. RPMs required:

Red Hat Linux 8.0:

SRPMS:


i386:



Red Hat Linux 9:

SRPMS:


i386:





6. Verification:

MD5 sum Package Name 606193c00a7fb419b4952b68f1245082 8.0/en/os/SRPMS/up2date-3.0.7.1-2.src.rpm be91944cf454244846a96b94a3efaa74 8.0/en/os/i386/up2date-3.0.7.1-2.i386.rpm 0adeb9cf7fff1754d183894fa40111bc 8.0/en/os/i386/up2date-gnome-3.0.7.1-2.i386.rpm 99d3b05223b596cf8d949c27b48e2ebd 9/en/os/SRPMS/up2date-3.1.23.1-5.src.rpm c6e89c3f118b5734a34d7275d8156596 9/en/os/i386/up2date-3.1.23.1-5.i386.rpm bf0b79cfeaaa6ed947609a27da5c2d65 9/en/os/i386/up2date-gnome-3.1.23.1-5.i386.rpm


These packages are GPG signed by Red Hat for security. Our key is available from Product Signing Keys - Red Hat Customer Portal

You can verify each package with the following command:

rpm --checksig -v

If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command:

md5sum


Summary

References

Package List


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2003:255-01
Issue date: 2003-08-08
Updated on: 2003-08-08
Product: Red Hat Linux
Keywords: up2date gpg Red Hat Network RHN rpm
Cross references:
Obsoletes:

Topic

Relevant Releases Architectures

Red Hat Linux 8.0 - i386

Red Hat Linux 9 - i386

Bugs Fixed

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here