[arch-general] Sébastien Luttringer and Tobias Powalowski
morten at linderud.pw
Sun Jul 2 22:07:07 UTC 2017
On Sun, Jul 02, 2017 at 11:55:35PM +0200, NicoHood wrote:
> Yes the GPG signature of the tag commit is checked. However you can
> attack the git metadata and set a tag to a different commit. If this
> commit is signed, but at an older stage which is vulnearable, we have an
> issue. Just one example. So we should always also secure the transport
The sign includes the hash. You would essentially have to trick Lennart into replacing the tag to a different commit,
and sign the tag. Creating a vulnerable but verified source for the PKGBUILD. At this point i think we have bigger
problems then whatever the PKGBUILD is doing...
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 833 bytes
Desc: not available
More information about the arch-general