Historical bug tracker for the Pacman package manager.
The pacman bug tracker has moved to gitlab:
https://gitlab.archlinux.org/pacman/pacman/-/issues
This tracker remains open for interaction with historical bugs during the transition period. Any new bugs reports will be closed without further action.
The pacman bug tracker has moved to gitlab:
https://gitlab.archlinux.org/pacman/pacman/-/issues
This tracker remains open for interaction with historical bugs during the transition period. Any new bugs reports will be closed without further action.
FS#69485 - Deprecate insecure checksums in makepkg
Attached to Project:
Pacman
Opened by Victor Engmark (l0b0) - Sunday, 31 January 2021, 09:09 GMT
Last edited by Allan McRae (Allan) - Sunday, 31 January 2021, 13:07 GMT
Opened by Victor Engmark (l0b0) - Sunday, 31 January 2021, 09:09 GMT
Last edited by Allan McRae (Allan) - Sunday, 31 January 2021, 13:07 GMT
|
DetailsDescription: makepkg currently supports md5sum and sha1sum, both of which are considered insecure. Marked as high severity since as far as I can tell a chosen-prefix attack against either of these are within reach of private persons (https://en.wikipedia.org/wiki/Collision_attack#Chosen-prefix_collision_attack).
Additional info: * makepkg (pacman) 5.2.2 Steps to reproduce: 1. Build any AUR package which uses "md5sums" or "sha1sums" in PKGBUILD. |
This task depends upon
Closed by Allan McRae (Allan)
Sunday, 31 January 2021, 13:07 GMT
Reason for closing: Won't implement
Sunday, 31 January 2021, 13:07 GMT
Reason for closing: Won't implement
If people in Arch Land want to discuss this further, reopen and move back to the Arch section of the bug tracker.