The reason for getting rid of the internal OpenPGP parser is that it turns out 
to have security vulnerabilities that are exploitable if someone does `gpg2 
--export --armor -o s.asc FINGERPRINT && rpmkeys --import s.asc`.  Patching 
these vulnerabilities isn’t practical, as it would require a whole bunch of 
logic nobody is interested in implementing.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/issues/2414#issuecomment-1829367779
You are receiving this because you are subscribed to this thread.

Message ID: <rpm-software-management/rpm/issues/2414/1829367...@github.com>
_______________________________________________
Rpm-maint mailing list
Rpm-maint@lists.rpm.org
http://lists.rpm.org/mailman/listinfo/rpm-maint

Reply via email to