CVE-2009-1358
CVE-2009-1358
apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=433091https://bugs.launchpad.net/ubuntu/+source/apt/+bug/356012http://secunia.com/advisories/34829http://secunia.com/advisories/34832http://secunia.com/advisories/34874https://exchange.xforce.ibmcloud.com/vulnerabilities/50086https://usn.ubuntu.com/762-1/http://www.debian.org/security/2009/dsa-1779http://www.securityfocus.com/bid/34630