VYPR
Medium severity6.5NVD Advisory· Published Jun 18, 2019· Updated Jun 17, 2026

CVE-2019-12875

CVE-2019-12875

Description

Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --keys-dir option that causes acceptance of an untrusted signing key.

Affected products

3
  • cpe:2.3:a:alpinelinux:abuild:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:alpinelinux:abuild:*:*:*:*:*:*:*:*range: <=3.4.0
    • (no CPE)range: <=3.4.0
  • Alpine Linux/abuilddescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.