Описание
APT before 1.0.4 does not properly validate source packages, which allows man-in-the-middle attackers to download and install Trojan horse packages by removing the Release signature.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 1.0.4ubuntu4 |
esm-infra-legacy/trusty | not-affected | 1.0.1ubuntu2.1 |
lucid | released | 0.7.25.3ubuntu9.15 |
precise | released | 0.8.16~exp12ubuntu10.17 |
saucy | released | 0.9.9.1~ubuntu3.2 |
trusty | released | 1.0.1ubuntu2.1 |
trusty/esm | not-affected | 1.0.1ubuntu2.1 |
upstream | released | 1.0.4 |
Показывать по
EPSS
4 Medium
CVSS2
Связанные уязвимости
APT before 1.0.4 does not properly validate source packages, which allows man-in-the-middle attackers to download and install Trojan horse packages by removing the Release signature.
APT before 1.0.4 does not properly validate source packages, which all ...
APT before 1.0.4 does not properly validate source packages, which allows man-in-the-middle attackers to download and install Trojan horse packages by removing the Release signature.
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить целостность и доступность защищаемой информации
EPSS
4 Medium
CVSS2