Описание
APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 0.8.15.1ubuntu2 |
| hardy | not-affected | code not present |
| lucid | not-affected | code not present |
| maverick | not-affected | code not present |
| natty | released | 0.8.13.2ubuntu4.1 |
| upstream | needs-triage |
Показывать по
4.3 Medium
CVSS2
Связанные уязвимости
APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.
APT before 0.8.15.2 does not properly validate inline GPG signatures, ...
APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.
4.3 Medium
CVSS2