VulnerabilityModified
CVE-2017-2623
It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering.
MEDIUM 5.3EPSS 1.03%
Does this matter?
Lower severity and a low EPSS score (1.03%). Track it; it rarely justifies an emergency change on its own.
Description
It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages with unsigned or badly signed content could fail to be rejected as expected. This issue is partially mitigated on RHEL Atomic Host, where certificate pinning is used by default.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 1.03% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- rpm-ostree/rpm-ostree · rpm-ostree/rpm-ostree-client · redhat/enterprise linux
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/96558Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:0444Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2623Issue Tracking, Third Party Advisory
- http://www.securityfocus.com/bid/96558Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:0444Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2623Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.