CVE-2009-1358: Critical severity kali linux package management (apt) vulnerability
apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1358?
CVE-2009-1358 has been classified as a critical severity vulnerability due to the possibility of remote code execution via malicious repositories.
How do I fix CVE-2009-1358?
To fix CVE-2009-1358, upgrade the apt package to version 0.7.21 or later.
What systems are affected by CVE-2009-1358?
CVE-2009-1358 affects Debian's Advanced Package Tool (apt) versions before 0.7.21.
What kind of attack does CVE-2009-1358 enable?
CVE-2009-1358 allows attackers to exploit the vulnerability by tricking apt into accepting invalid signed repositories.
Is CVE-2009-1358 an easy vulnerability to exploit?
Yes, CVE-2009-1358 can be easily exploited by remote attackers if the vulnerable version of apt is in use.