LWN.net Logo

apt: repository credential disclosure

Package(s):apt CVE #(s):CVE-2011-3634
Created:November 28, 2011 Updated:November 30, 2011
Description: From the Ubuntu advisory:

It was discovered that APT incorrectly handled the Verify-Host configuration option. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could potentially be used to steal repository credentials. This issue only affected Ubuntu 10.04 LTS and 10.10.

Alerts:
Ubuntu USN-1283-1 2011-11-28

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds