First published: Mon Nov 25 2019(Updated: )
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Advanced Package Tool | ||
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
debian/apt | <=2.2.4<=2.6.1<=2.9.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2011-3374 is medium, with a severity value of 3.7.
CVE-2011-3374 affects apt in all versions.
The potential impact of CVE-2011-3374 is a man-in-the-middle attack.
CVE-2011-3374 affects the following software versions: 0.7.9ubuntu17.3, 0.7.25.3ubuntu9.7, 0.8.3ubuntu7.2, 0.8.13.2ubuntu4.2 for Ubuntu, and 1.8.2.3 up to 2.7.6 for Debian.
To fix CVE-2011-3374 in apt, you should update to the latest available version provided by the official distribution's package repository.