The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source.
| Software | From | Fixed in |
|---|---|---|
| redhat / redhat_package_manager | 4.0.2-71 | 4.0.2-71.x |
| redhat / redhat_package_manager | 4.0.2-72 | 4.0.2-72.x |
| redhat / redhat_package_manager | 4.0.3 | 4.0.3.x |
| redhat / redhat_package_manager | 4.0.4 | 4.0.4.x |