Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fgp5-9jf3-jfrv

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitrary code via a crafted package.

The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitrary code via a crafted package.

EPSS

Процентиль: 71%
0.00688
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 11 лет назад

The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitrary code via a crafted package.

nvd
больше 11 лет назад

The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitrary code via a crafted package.

debian
больше 11 лет назад

The apt-get download command in APT before 1.0.9 does not properly val ...

EPSS

Процентиль: 71%
0.00688
Низкий

Дефекты

CWE-20