[Rpm-maint] [rpm-software-management/rpm] Add deltarpm support (#433)

Jeff Johnson notifications at github.com
Tue Apr 24 13:12:44 UTC 2018


Note that early unpacking/undeltafying of payload files is also going to disable file digest verification while installing files.

This potentially exposes a TOCTOU (time of check to time of use) security flaw unless you also choose to verify the file digest before renaming.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/issues/433#issuecomment-383925034
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rpm.org/pipermail/rpm-maint/attachments/20180424/677aa0bf/attachment.html>


More information about the Rpm-maint mailing list