VYPR
Unrated severityNVD Advisory· Published Sep 6, 2007· Updated Apr 23, 2026

CVE-2007-4739

CVE-2007-4739

Description

reprepro 1.3.0 through 2.2.3 does not properly verify signatures when updating repositories, which allows remote attackers to construct and distribute an ostensibly valid Release.gpg file by signing it with an unknown key, related to the update command.

Affected products

8
  • Debian/Reprepro8 versions
    cpe:2.3:a:debian:reprepro:1.3.0:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:debian:reprepro:1.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:debian:reprepro:1.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:debian:reprepro:2.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:debian:reprepro:2.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:debian:reprepro:2.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:debian:reprepro:2.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:debian:reprepro:2.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:debian:reprepro:2.2.3:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

8

News mentions

0

No linked articles in our index yet.