[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#887830: debian-cd: *.jigdo files should be listed in the *SUMS files

Package: debian-cd
Severity: normal
Tags: upstream

Dear Maintainer,

as described in
the *.jigdo files are not listed in the checksum files *SUMS.
There is no way provided to check the authenticity of *.jigdo before
downloading by jigdo-lite begins.

The *.jigdo file provides package file paths, the URLs of fallback
mirrors, and the cheksum of the *.template file. So *.template can
inflate to an image of arbitrary size and jigdo-lite can be lured into
downloading arbitrary URLs.

Have a nice day :)


Reply to: