LWN.net Logo

software-properties: man-in-the-middle attack

Package(s):software-properties CVE #(s):
Created:October 2, 2012 Updated:October 3, 2012
Description: From the Ubuntu advisory:

It was discovered that the apt-add-repository tool incorrectly validated PPA GPG keys when importing from a keyserver. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to install altered package repository GPG keys.

Alerts:
Ubuntu USN-1588-1 2012-10-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds