First published: Wed Jul 27 2011(Updated: )
APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Advanced Package Tool | <0.8.15.2 | |
Canonical Ubuntu Linux | =11.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.