Lucene search

K
ubuntuUbuntuUSN-1385-1
HistoryMar 06, 2012 - 12:00 a.m.

APT vulnerability

2012-03-0600:00:00
ubuntu.com
33

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

35.2%

Releases

  • Ubuntu 11.10
  • Ubuntu 11.04

Packages

  • apt - Advanced front-end for dpkg

Details

Simon Ruderich discovered that APT incorrectly handled repositories that
use InRelease files. The default Ubuntu repositories do not use InRelease
files, so this issue only affected third-party repositories. If a remote
attacker were able to perform a machine-in-the-middle attack, this flaw could
potentially be used to install altered packages.

OSVersionArchitecturePackageVersionFilename
Ubuntu11.10noarchapt< 0.8.16~exp5ubuntu13.2UNKNOWN
Ubuntu11.10noarchapt-transport-https< 0.8.16~exp5ubuntu13.2UNKNOWN
Ubuntu11.10noarchapt-utils< 0.8.16~exp5ubuntu13.2UNKNOWN
Ubuntu11.10noarchlibapt-inst1.3< 0.8.16~exp5ubuntu13.2UNKNOWN
Ubuntu11.10noarchlibapt-pkg-dev< 0.8.16~exp5ubuntu13.2UNKNOWN
Ubuntu11.10noarchlibapt-pkg4.11< 0.8.16~exp5ubuntu13.2UNKNOWN
Ubuntu11.04noarchapt< 0.8.13.2ubuntu4.4UNKNOWN
Ubuntu11.04noarchapt-transport-https< 0.8.13.2ubuntu4.4UNKNOWN
Ubuntu11.04noarchapt-utils< 0.8.13.2ubuntu4.4UNKNOWN
Ubuntu11.04noarchlibapt-pkg-dev< 0.8.13.2ubuntu4.4UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

35.2%