Field Assessment
AI analysis pending.
CVE
CVE-2014-0022
Severity
MEDIUM
CVSS
5
EPSS
2.41%
Original Filing — NVD Description
The installUpdates function in yum-cron/yum-cron.py in yum 3.4.3 and earlier does not properly check the return value of the sigCheckPkg function, which allows remote attackers to bypass the RMP package signing restriction via an unsigned package.