> @pmatilai Could you please share if any ETA on the fix? If this takes longer, 
> we can implement workarounds to downgrade in our applications rather than 
> waiting for the actual fix.

Please do not downgrade; this exposes you to a severe security hole 
(CVE-2021-20271) that allows for signature verification bypass and remote code 
execution.  I will make a PR here, but please file a support ticket with 
install4j.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/issues/1635#issuecomment-836842779
_______________________________________________
Rpm-maint mailing list
Rpm-maint@lists.rpm.org
http://lists.rpm.org/mailman/listinfo/rpm-maint

Reply via email to