FS#69485 - Deprecate insecure checksums in makepkg
Attached to Project:
Pacman
Opened by Victor Engmark (l0b0) - Sunday, 31 January 2021, 09:09 GMT
Last edited by Allan McRae (Allan) - Sunday, 31 January 2021, 13:07 GMT
Opened by Victor Engmark (l0b0) - Sunday, 31 January 2021, 09:09 GMT
Last edited by Allan McRae (Allan) - Sunday, 31 January 2021, 13:07 GMT
|
Details
Description: makepkg currently supports md5sum and sha1sum,
both of which are considered insecure. Marked as high
severity since as far as I can tell a chosen-prefix attack
against either of these are within reach of private persons
(https://en.wikipedia.org/wiki/Collision_attack#Chosen-prefix_collision_attack).
Additional info: * makepkg (pacman) 5.2.2 Steps to reproduce: 1. Build any AUR package which uses "md5sums" or "sha1sums" in PKGBUILD. |
This task depends upon
Closed by Allan McRae (Allan)
Sunday, 31 January 2021, 13:07 GMT
Reason for closing: Won't implement
Sunday, 31 January 2021, 13:07 GMT
Reason for closing: Won't implement
If people in Arch Land want to discuss this further, reopen and move back to the Arch section of the bug tracker.