// For flags

CVE-2014-0022

yum: yum-cron installs unsigned packages

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The installUpdates function in yum-cron/yum-cron.py in yum 3.4.3 and earlier does not properly check the return value of the sigCheckPkg function, which allows remote attackers to bypass the RMP package signing restriction via an unsigned package.

La función installUpdates en yum-cron/yum-cron.py en yum 3.4.3 y anteriores no chequea apropiadamente el valor de retorno de la función sigCheckPkg, lo cual permite a atacantes remotos sortear la restricción de firmado de paquetes RMP a través de un paquete no firmado.

It was discovered that yum-updatesd did not properly perform RPM package signature checks. When yum-updatesd was configured to automatically install updates, a remote attacker could use this flaw to install a malicious update on the target system using an unsigned RPM or an RPM signed with an untrusted key.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-12-03 CVE Reserved
  • 2014-01-26 CVE Published
  • 2023-12-09 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
  • CWE-347: Improper Verification of Cryptographic Signature
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Baseurl
Search vendor "Baseurl"
Yum
Search vendor "Baseurl" for product "Yum"
<= 3.4.3
Search vendor "Baseurl" for product "Yum" and version " <= 3.4.3"
-
Affected
Baseurl
Search vendor "Baseurl"
Yum
Search vendor "Baseurl" for product "Yum"
3.4.0
Search vendor "Baseurl" for product "Yum" and version "3.4.0"
-
Affected
Baseurl
Search vendor "Baseurl"
Yum
Search vendor "Baseurl" for product "Yum"
3.4.1
Search vendor "Baseurl" for product "Yum" and version "3.4.1"
-
Affected
Baseurl
Search vendor "Baseurl"
Yum
Search vendor "Baseurl" for product "Yum"
3.4.2
Search vendor "Baseurl" for product "Yum" and version "3.4.2"
-
Affected