First published: Mon Aug 20 2018(Updated: )
The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verification for the InRelease file of a fallback mirror, aka mirrorfail.
Credit: security@debian.org security@debian.org security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Canonical Ubuntu Linux | =18.04 | |
Debian Advanced Package Tool | >=1.6.0<1.6.4 | |
Debian Advanced Package Tool | =1.7.0-alpha | |
Debian Advanced Package Tool | =1.7.0-alpha1 | |
Debian Advanced Package Tool | =1.7.0-alpha2 | |
ubuntu/apt | <1.6.3ubuntu0.1 | 1.6.3ubuntu0.1 |
debian/apt | 2.2.4 2.6.1 2.9.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0501 is a vulnerability in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 that mishandles gpg signature verification for the InRelease file of a fallback mirror.
CVE-2018-0501 has a severity rating of 5.9 (medium).
CVE-2018-0501 affects the following software: - APT 1.6.x before 1.6.4 - APT 1.7.x before 1.7.0~alpha3 - Canonical Ubuntu Linux 18.04 LTS - Debian Advanced Package Tool 1.6.0 to 1.6.4 - Debian Advanced Package Tool 1.7.0-alpha - Debian Advanced Package Tool 1.7.0-alpha1 - Debian Advanced Package Tool 1.7.0-alpha2 - Debian Advanced Package Tool 1.8.2.2, 1.8.2.3 - Debian Advanced Package Tool 2.2.4 - Debian Advanced Package Tool 2.6.1 - Debian Advanced Package Tool 2.7.6
To fix CVE-2018-0501, update APT to version 1.6.4 or higher, or version 1.7.0~alpha3 or higher. For Ubuntu, update the 'apt' package to version 1.6.3ubuntu0.1 or higher. Make sure to apply the latest updates for Canonical Ubuntu Linux and Debian Advanced Package Tool as well.
You can find more information about CVE-2018-0501 at the following references: - [https://mirror.fail](https://mirror.fail) - [https://salsa.debian.org/apt-team/apt/commit/29658a3a74af49e2a24e17bdebb20e1612aac3ec](https://salsa.debian.org/apt-team/apt/commit/29658a3a74af49e2a24e17bdebb20e1612aac3ec) - [https://salsa.debian.org/apt-team/apt/commit/aebd4278bacc728ab00ebe31556983e140f60e47](https://salsa.debian.org/apt-team/apt/commit/aebd4278bacc728ab00ebe31556983e140f60e47)