3 ms·
Yes, it's true... for redhat the worst rpm cve I could see from a quick google was back in 2012. The CVE you mention is about the transport part, it's not easy
by outsomnia 6y ago
Yes, it's true... for redhat the worst rpm cve I could see from a quick google was back in 2012.
The CVE you mention is about the transport part, it's not easy to get right and everything that goes on the network is at some risk of that. Still that seems a different kind of implication than nobody checked if packages could be tampered successfully for 3 years and afterwards nobody changed the infrastructure.