Deltarpm *not* ready for new RPM checksums (was Re: Ready for new RPM version?)

Alexander Boström abo at stacken.kth.se
Sat Apr 18 14:44:08 UTC 2009


Axel Thimm skrev:

> Sorry for jumping in that late, but assuming a malicious deltarpm that
> could fake a matching md5 sum to pass validation, wouldn't it get
> applied and make that a security issue?

I assume that deltarpms are (required to be) signed just like full rpms.

/abo




More information about the fedora-devel-list mailing list