LWN.net Logo

apt: altered package installation

Package(s):apt CVE #(s):
Created:September 23, 2011 Updated:September 29, 2011
Description: From the Ubuntu advisory:

It was discovered that the apt-key utility incorrectly verified GPG keys when downloaded via the net-update option. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could potentially be used to install altered packages. This update corrects the issue by disabling the net-update option completely. A future update will re-enable the option with corrected verification.

Alerts:
Ubuntu USN-1215-1 2011-09-22

(Log in to post comments)

apt: altered package installation

Posted Sep 29, 2011 9:19 UTC (Thu) by juliank (subscriber, #45896) [Link]

Please note that Debian is not affected, as that it has net-update disabled.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds