First published: Tue Apr 15 2014(Updated: )
The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before 0.8.16~exp13, when updating from repositories that use InRelease files, allows man-in-the-middle attackers to install arbitrary packages by preventing a user from downloading the new InRelease file, which leaves the original InRelease file active and makes it more difficult to detect that the Packages file is modified and unsigned.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Advanced Package Tool | <=0.8.16\~exp12 | |
Debian Advanced Package Tool | =0.8.11 | |
Debian Advanced Package Tool | =0.8.12 | |
Debian Advanced Package Tool | =0.8.13 | |
Debian Advanced Package Tool | =0.8.14 | |
Debian Advanced Package Tool | =0.8.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0214 is classified as a critical vulnerability due to its potential to allow man-in-the-middle attacks.
To mitigate CVE-2012-0214, upgrade the Advanced Package Tool to version 0.8.16~exp13 or later.
CVE-2012-0214 affects Advanced Package Tool versions 0.8.11 through 0.8.15.10 and includes 0.8.16 before 0.8.16~exp13.
CVE-2012-0214 facilitates man-in-the-middle attacks that can allow an attacker to install arbitrary packages.
Yes, a patch is available in the form of a software update for Advanced Package Tool that addresses CVE-2012-0214.