CVE-2017-2623
rpm-ostree-client: fails to check gpg package signatures when layering
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially mitigated on RHEL Atomic Host, where certificate pinning is used by default.
Se ha descubierto que rpm-ostree y rpm-ostree-client en versiones anteriores a la 2017.3 no comprueban correctamente las firmas GPG en los paquetes al crear las capas. Los paquetes con contenido sin firmar o mal firmado podrían no ser rechazados tal y como se esperaría. Este problema se mitiga parcialmente en RHEL Atomic Host, donde se utiliza la fijación de certificados por defecto.
It was discovered that rpm-ostree and rpm-ostree-client fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially mitigated on RHEL Atomic Host, where certificate pinning is used by default.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-12-01 CVE Reserved
- 2017-03-04 CVE Published
- 2023-12-18 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-295: Improper Certificate Validation
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/96558 | Third Party Advisory | |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2623 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2017:0444 | 2019-10-09 | |
https://access.redhat.com/security/cve/CVE-2017-2623 | 2017-03-02 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1422157 | 2017-03-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rpm-ostree Search vendor "Rpm-ostree" | Rpm-ostree Search vendor "Rpm-ostree" for product "Rpm-ostree" | < 2017.3 Search vendor "Rpm-ostree" for product "Rpm-ostree" and version " < 2017.3" | - |
Affected
| ||||||
Rpm-ostree Search vendor "Rpm-ostree" | Rpm-ostree-client Search vendor "Rpm-ostree" for product "Rpm-ostree-client" | < 2017.3 Search vendor "Rpm-ostree" for product "Rpm-ostree-client" and version " < 2017.3" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 7.0 Search vendor "Redhat" for product "Enterprise Linux" and version "7.0" | - |
Affected
|