Bug#956276: runescape: downloads unverified binary and runs it

Ivo De Decker ivodd at debian.org
Thu Apr 9 10:36:24 BST 2020


package: runescape
severity: serious

Hi,

It seems runescape downloads a binary and runs it, without verifying its
integrity. At least the download happens using https, but no other
verification is done.

Cheers,

Ivo



More information about the Pkg-games-devel mailing list