Skip to content
Commit 02b2090e authored by Hans-Christoph Steiner's avatar Hans-Christoph Steiner
Browse files

check repo index timestamps to prevent rollback attacks

A hacked fdroid server could "replay" old index.jar files known to have
apps with vulnerabilities in it.  That provides a long window of time for
exploiting that vulnerability.  By checking that the timestamp of an update
is never older than the current index, this attack is prevented.
parent 014ab2d2
Loading
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment