LWN.net Logo

apt: man-in-the-middle attack

Package(s):apt CVE #(s):CVE-2012-0954
Created:June 18, 2012 Updated:June 20, 2012
Description: From the Ubuntu advisory:

Georgi Guninski discovered that APT did not properly validate imported keyrings via apt-key net-update. USN-1475-1 added additional verification for imported keyrings, but it was insufficient. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could potentially be used to install altered packages. This update corrects the issue by disabling the net-update option completely. A future update will re-enable the option with corrected verification.

Alerts:
Ubuntu USN-1477-1 2012-06-15
Ubuntu USN-1475-1 2012-06-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds