mirror of
https://github.com/f-droid/fdroidclient.git
synced 2026-02-06 21:22:50 -05:00
A hacked fdroid server could "replay" old index.jar files known to have apps with vulnerabilities in it. That provides a long window of time for exploiting that vulnerability. By checking that the timestamp of an update is never older than the current index, this attack is prevented.