Vulnerabilities Related to GPG-signing
Abstract
This page documents CVS vulnerabilities with respect to GPG-signing. It is intended to be a living document, expanded and updated as new vulnerabilities become known and as old vulnerabilities are covered.
The vulnerabilities that this page discusses are those related to GPG-signing commits: vulnerabilities that GPG-signing addresses, and new vulnerabilities introduced by GPG-signing.
See GPG-Signed Commits for details on GPG signing.
Vulnerabilities
There are three types of vulnerabilities: direct modification of the RCS ,v files in the repository, and compromising the CVS server software, and compromising the CVS client software {{ref|otherattacks}}.
Hacking the Repository
Compromised Server
Compromised Client
A compromised server
References
GPG-Signed Commits<br/>
![[ Valid XHTML 1.0! ]](/branding/w3c-valid-xhtml10-44x16.png)
![[ Valid CSS! ]](/branding/w3c-valid-css-44x16.png)
