Описание
APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to have unspecified impact via crafted repository data.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 1.0.8ubuntu2 |
| esm-infra-legacy/trusty | released | 1.0.1ubuntu2.3 |
| lucid | released | 0.7.25.3ubuntu9.16 |
| precise | released | 0.8.16~exp12ubuntu10.19 |
| trusty | released | 1.0.1ubuntu2.3 |
| trusty/esm | released | 1.0.1ubuntu2.3 |
| upstream | needs-triage |
Показывать по
EPSS
6.8 Medium
CVSS2
Связанные уязвимости
APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to have unspecified impact via crafted repository data.
APT before 1.0.9 does not "invalidate repository data" when moving fro ...
APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to have unspecified impact via crafted repository data.
EPSS
6.8 Medium
CVSS2