apt Verify-Host Configuration Signature Verification Vulnerability
BID:50838
Info
apt Verify-Host Configuration Signature Verification Vulnerability
| Bugtraq ID: | 50838 |
| Class: | Design Error |
| CVE: |
CVE-2011-3634 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2011 12:00AM |
| Updated: | Nov 29 2011 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 8.04 LTS 0 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 11.04 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.10 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 LTS Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Debian apt 0 |
| Not Vulnerable: | |
Discussion
apt Verify-Host Configuration Signature Verification Vulnerability
apt is prone to a signature-verification vulnerability.
An attacker may exploit this issue through man-in-the-middle attacks. Successful attacks may allow the attacker to execute arbitrary code on a vulnerable computer.
apt is prone to a signature-verification vulnerability.
An attacker may exploit this issue through man-in-the-middle attacks. Successful attacks may allow the attacker to execute arbitrary code on a vulnerable computer.
Exploit / POC
apt Verify-Host Configuration Signature Verification Vulnerability
Attackers can exploit this issue using readily available tools.
Attackers can exploit this issue using readily available tools.
Solution / Fix
apt Verify-Host Configuration Signature Verification Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
apt Verify-Host Configuration Signature Verification Vulnerability
References:
References:
- apt Product Page (Debian)