apt Repository Inline GPG Signature Verification Vulnerability
BID:48671
Info
apt Repository Inline GPG Signature Verification Vulnerability
| Bugtraq ID: | 48671 |
| Class: | Design Error |
| CVE: |
CVE-2011-1829 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2011 12:00AM |
| Updated: | Jul 13 2011 12:00AM |
| Credit: | William Grant |
| Vulnerable: |
Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Debian apt 0.7.21 Debian apt 0.7.20 .2 Debian apt 0.7.20 .1 Debian apt 0.7.20 |
| Not Vulnerable: | |
Discussion
apt Repository Inline GPG Signature Verification Vulnerability
apt is prone to a signature-verification vulnerability.
An attacker may exploit this issue through man-in-the-middle attacks. Successful attacks may allow the attacker to execute arbitrary code on a vulnerable computer.
apt is prone to a signature-verification vulnerability.
An attacker may exploit this issue through man-in-the-middle attacks. Successful attacks may allow the attacker to execute arbitrary code on a vulnerable computer.
Exploit / POC
apt Repository Inline GPG Signature Verification Vulnerability
An attacker can exploit this issue by using readily available utilities.
An attacker can exploit this issue by using readily available utilities.
Solution / Fix
apt Repository Inline GPG Signature Verification Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
apt Repository Inline GPG Signature Verification Vulnerability
References:
References:
- apt Product Page (Debian)