Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 21 Apr 2020 12:52:28 -0400
From: Santiago Torres <torresariass@...il.com>
To: oss-security@...ts.openwall.com
Subject: Re: Pacman package manager - taking untrusted input

On Tue, Apr 21, 2020 at 04:27:08PM +0000, jellicent@...tonmail.com wrote:
> The Pacman package manager, used by Arch Linux and its 10+ derivatives,
> introduces a critical security flaw in its current state.
> ... The database, however, is not signed.

Or
 
> The code supports database signatures, so the real issue is the distro
> infrastructure.

Pick one please.

> [1] https://wiki.archlinux.org/index.php/Pacman/Package_signing

Download attachment "signature.asc" of type "application/pgp-signature" (834 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.