• [^] # Re: Modif de métadonnées

    Posté par (site web personnel) . En réponse au journal La sécurité des gestionnaires de paquets. Évalué à 3.

    Extrait de l'article :

    "As mentioned, the lack of signed metadata allows attackers to lie to clients about what each package provides and requires.
    By lying to clients about this information, an attacker can significantly increase the chances of a client installing a vulnerable package.
    For example, if package foo has a vulnerability the attacker knows how to exploit, the attacker can provide metadata that says every package depends on package foo, in order to ensure that the client installs it when installing any other package.
    "

    Donc l'idée c'est que quand tu sait qu'un paquet quelconque du dépôt a un trou de sécurité tu peux forcer son installation lors de l'installation de n'importe quel autre paquet.