Lucene search

K
cvelistDebianCVELIST:CVE-2018-0501
HistoryAug 21, 2018 - 12:00 a.m.

CVE-2018-0501

2018-08-2100:00:00
debian
www.cve.org
5

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

55.6%

The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verification for the InRelease file of a fallback mirror, aka mirrorfail.

CNA Affected

[
  {
    "product": "APT 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "APT 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3"
      }
    ]
  }
]

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

55.6%