Описание
ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 0.82.3 |
| hardy | ignored | end of life |
| lucid | released | 0.75.10.2 |
| maverick | released | 0.76.7.1 |
| natty | released | 0.80.9.1 |
| oneiric | released | 0.81.13.3 |
| upstream | needs-triage |
Показывать по
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.
ppa.py in Software Properties before 0.81.13.3 does not validate the s ...
ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.
EPSS
4.3 Medium
CVSS2