Stories
Slash Boxes
Comments
typodupeerror delete not in

+-   Package Managers an Achilles Heel? on Thursday July 10 2008, @10:40AM Anonymous Coward

Submitted by Anonymous Coward on Thursday July 10 2008, @10:40AM
security
An anonymous reader writes "A group of researchers from the University of Arizona have released a study that takes a look at the security of ten popular package managers. They were able to show all ten were vulnerable to attacks from a mirror or man-in-the-middle that allow an attacker to (along with other things) crash the system or obtain root access. Furthermore, the researchers created a fictitious administrator and company name and were able to lease a server and get it listed as an official mirror for all the distributions they tried (Ubuntu, Debian, Fedora, CentOS, and OpenSUSE).

This begs the question, what keeps you up at night, the thought of attacks on your package manager or previously discussed and patched vulnerability in DNS."
submission

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
VMS is like a nightmare about RXS-11M.