Security Advisory
CVE-2015-1337
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk images and have unspecified other impact via a 403 (aka Forbidden) response.