Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Fri, 11 Nov 2016 19:37:44 +0100
From: Jakub Wilk <jwilk@...lk.net>
To: oss-security@...ts.openwall.com
Subject: Pipelight: broken validation of dependency installer signature

Pipelight <http://pipelight.net/cms/about.html> is a wrapper for using Windows 
plugins in Linux browsers. The software comes with an option to update the 
install-dependency script, which contains the plugin database. The downloaded 
code was supposed to be verified against a GPG key, but the verification code 
was broken.

Bug report: https://bugs.launchpad.net/pipelight/+bug/1632502
Committed fix: https://bitbucket.org/mmueller2012/pipelight/commits/c9fc745d46be

-- 
Jakub Wilk

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.