DescriptionThe signature verification functionality in the YaST Online Update (YOU) script handling relies on a gpg feature that is not intended for signature verification, which prevents YOU from detecting malicious scripts or code that do not pass the signature check when gpg 1.4.x is being used.
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
|National Vulnerability Database|
SUSE Security Advisories:
- SUSE-SA:2006:013, published Wed, 01 Mar 2006 11:00:00 +0000
SUSE Timeline for this CVECVE page created: Fri Jun 28 01:42:33 2013
CVE page last modified: Fri Oct 7 12:45:32 2022