CVE-2016-1252: Medium severity kali linux package management (apt) vulnerability
The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and in Ubuntu 16.10 before 1.3.2ubuntu0.1 allows man-in-the-middle attackers to bypass a repository-signing protection mechanism by leveraging improper error handling when validating InRelease file signatures.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-1252?
CVE-2016-1252 is a vulnerability that allows man-in-the-middle attackers to bypass repository-signing protection mechanism in the apt package.
Which software packages are affected by CVE-2016-1252?
The apt package in Debian jessie before 1.0.9.8.4, Debian unstable before 1.4~beta2, Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and Ubuntu 16.10 before 1.3.2ubuntu0.1 are affected.
What is the severity of CVE-2016-1252?
The severity of CVE-2016-1252 is medium with a CVSS score of 5.9.
How do I fix CVE-2016-1252?
To fix CVE-2016-1252, it is recommended to update the apt package to version 1.8.2.3, 1.8.2.2, 2.2.4, 2.6.1, or 2.7.6, depending on the affected software package.
Where can I find more information about CVE-2016-1252?
You can find more information about CVE-2016-1252 at the following references: - [Ubuntu Bug Report](https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1647467) - [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2016-1252) - [Packet Storm Security](http://packetstormsecurity.com/files/140145/apt-Repository-Signing-Bypass.html)