Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-1358

Опубликовано: 21 апр. 2009
Источник: ubuntu
Приоритет: medium
CVSS2: 10

Описание

apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.

РелизСтатусПримечание
dapper

released

0.6.43.3ubuntu3.1
devel

released

0.7.20.2ubuntu6
hardy

released

0.7.9ubuntu17.2
intrepid

released

0.7.14ubuntu6.1
upstream

released

0.7.21

Показывать по

10 Critical

CVSS2

Связанные уязвимости

nvd
больше 16 лет назад

apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.

debian
больше 16 лет назад

apt-get in apt before 0.7.21 does not check for the correct error code ...

github
больше 3 лет назад

apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.

fstec
почти 11 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

fstec
почти 11 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

10 Critical

CVSS2