Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-0022
Description:The installUpdates function in yum-cron/yum-cron.py in yum 3.4.3 and earlier does not properly check the return value of the sigCheckPkg function, which allows remote attackers to bypass the RMP package signing restriction via an unsigned package.
Test IDs: 1.3.6.1.4.1.25623.1.0.123342   1.3.6.1.4.1.25623.1.0.881982   1.3.6.1.4.1.25623.1.0.871215   1.3.6.1.4.1.25623.1.0.120356  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-0022
56637
http://secunia.com/advisories/56637
65119
http://www.securityfocus.com/bid/65119
http://yum.baseurl.org/gitweb?p=yum.git%3Ba=commitdiff%3Bh=9df69e5794
http://yum.baseurl.org/gitweb?p=yum.git%3Ba=commitdiff%3Bh=9df69e5794
https://bugzilla.redhat.com/show_bug.cgi?id=1052440
https://bugzilla.redhat.com/show_bug.cgi?id=1052440
https://bugzilla.redhat.com/show_bug.cgi?id=1057377
https://bugzilla.redhat.com/show_bug.cgi?id=1057377




© 1998-2025 E-Soft Inc. All rights reserved.