The installUpdates function in yum-cron/yum-cron.py in yum 3.4.3 and earlier does not properly check the return value of the sigCheckPkg function, which allows remote attackers to bypass the RMP package signing restriction via an unsigned package.
| Software | From | Fixed in |
|---|---|---|
| baseurl / yum | 3.4.1 | 3.4.1.x |
| baseurl / yum | - | 3.4.3.x |
| baseurl / yum | 3.4.2 | 3.4.2.x |
| baseurl / yum | 3.4.0 | 3.4.0.x |