Show filters
25 Total Results
Displaying 21-25 of 25
Sort by:
Attacker Value
Unknown

CVE-2012-0954

Disclosure Date: June 19, 2012 (last updated October 04, 2023)
APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install altered packages via a man-in-the-middle (MITM) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3587.
0
Attacker Value
Unknown

CVE-2012-3587

Disclosure Date: June 19, 2012 (last updated October 04, 2023)
APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install Trojan horse packages via a man-in-the-middle (MITM) attack.
0
Attacker Value
Unknown

CVE-2011-1829

Disclosure Date: July 27, 2011 (last updated October 04, 2023)
APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.
0
Attacker Value
Unknown

CVE-2009-1358

Disclosure Date: April 21, 2009 (last updated October 04, 2023)
apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.
0
Attacker Value
Unknown

CVE-2009-1300

Disclosure Date: April 16, 2009 (last updated October 04, 2023)
apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight.
0