CVE-2009-1358
CVE-2009-1358
apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=433091https://bugs.launchpad.net/ubuntu/+source/apt/+bug/356012http://secunia.com/advisories/34829http://secunia.com/advisories/34832http://secunia.com/advisories/34874https://exchange.xforce.ibmcloud.com/vulnerabilities/50086https://usn.ubuntu.com/762-1/http://www.debian.org/security/2009/dsa-1779http://www.securityfocus.com/bid/34630