LWN.net Logo

apt: altered package installation

Package(s):apt CVE #(s):CVE-2013-1051
Created:March 15, 2013 Updated:March 20, 2013
Description:

From the Ubuntu advisory:

Ansgar Burchardt discovered that APT incorrectly handled repositories that use InRelease files. The default Ubuntu repositories do not use InRelease files, so this issue only affected third-party repositories. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could potentially be used to install altered packages.

Alerts:
Ubuntu USN-1762-1 2013-03-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds