LWN.net Logo

apt: incorrect signature checking

Package(s):apt CVE #(s):CVE-2009-1358
Created:April 27, 2009 Updated:April 29, 2009
Description:

From the Debian advisory:

CVE-2009-1358: A repository that has been signed with an expired or revoked OpenPGP key would still be considered valid by APT.

Alerts:
Debian DSA-1779-1 2009-04-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds