Description
APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2011-1827 | APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message. |
Ubuntu USN |
USN-1169-1 | APT vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2024-08-06T22:37:25.813Z
Reserved: 2011-04-27T00:00:00.000Z
Link: CVE-2011-1829
No data.
Status : Modified
Published: 2011-07-27T02:55:01.540
Modified: 2026-04-29T01:13:23.040
Link: CVE-2011-1829
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN