7. Verification:
MD5 sum Package Name
-------------------------------------------------------------------------
53856e0c3219de2fcb4e56600b4eb3b9 7.0/en/os/SRPMS/ncurses4-5.0-5.src.rpm
b470c5cf9eaaa4710a09e114aced3f4d 7.0/en/os/alpha/ncurses4-5.0-5.alpha.rpm
b5ad8bc36c129534192e0dbce582f5ed 7.0/en/os/i386/ncurses4-5.0-5.i386.rpm
53856e0c3219de2fcb4e56600b4eb3b9 7.1/en/os/SRPMS/ncurses4-5.0-5.src.rpm
b470c5cf9eaaa4710a09e114aced3f4d 7.1/en/os/alpha/ncurses4-5.0-5.alpha.rpm
b5ad8bc36c129534192e0dbce582f5ed 7.1/en/os/i386/ncurses4-5.0-5.i386.rpm
53856e0c3219de2fcb4e56600b4eb3b9 7.2/en/os/SRPMS/ncurses4-5.0-5.src.rpm
b5ad8bc36c129534192e0dbce582f5ed 7.2/en/os/i386/ncurses4-5.0-5.i386.rpm
These packages are GPG signed by Red Hat, Inc. for security. Our key is available at:
http://www.redhat.com/about/contact.html
You can verify each package with the following command: rpm --checksig filename
If you only wish to verify that each package has not been corrupted or tampered with,
examine only the md5sum with the following command: rpm --checksig --nogpg filename
Note that you need RPM >= 3.0 to check GnuPG keys.
8. References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0062