LWN.net Logo

apt: incorrect signature validation

Package(s):apt CVE #(s):CVE-2011-1829
Created:July 13, 2011 Updated:July 13, 2011
Description: The apt utility does not correctly check GPG signatures, enabling a man-in-the-middle attacker to force the installation of malicious packages.
Alerts:
Ubuntu USN-1169-1 2011-07-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds