Lucene search

K
ubuntuUbuntuUSN-1762-1
HistoryMar 14, 2013 - 12:00 a.m.

APT vulnerability

2013-03-1400:00:00
ubuntu.com
30

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

32.4%

Releases

  • Ubuntu 12.10
  • Ubuntu 12.04
  • Ubuntu 11.10

Packages

  • apt - Advanced front-end for dpkg

Details

Ansgar Burchardt discovered that APT incorrectly handled InRelease files.
If a remote attacker were able to perform a machine-in-the-middle attack, this
flaw could potentially be used to install altered packages.

This update corrects the issue by disabling InRelease file support
completely. Please note that this update breaks third-party repositories
that provide only a InRelease file and no separate Release and Release.gpg
files. The default Ubuntu repositories do not use InRelease files.

OSVersionArchitecturePackageVersionFilename
Ubuntu12.10noarchapt< 0.9.7.5ubuntu5.4UNKNOWN
Ubuntu12.10noarchapt-transport-https< 0.9.7.5ubuntu5.4UNKNOWN
Ubuntu12.10noarchapt-utils< 0.9.7.5ubuntu5.4UNKNOWN
Ubuntu12.10noarchlibapt-inst1.5< 0.9.7.5ubuntu5.4UNKNOWN
Ubuntu12.10noarchlibapt-pkg-dev< 0.9.7.5ubuntu5.4UNKNOWN
Ubuntu12.10noarchlibapt-pkg4.12< 0.9.7.5ubuntu5.4UNKNOWN
Ubuntu12.04noarchapt< 0.8.16~exp12ubuntu10.10UNKNOWN
Ubuntu12.04noarchapt-transport-https< 0.8.16~exp12ubuntu10.10UNKNOWN
Ubuntu12.04noarchapt-utils< 0.8.16~exp12ubuntu10.10UNKNOWN
Ubuntu12.04noarchlibapt-inst1.4< 0.8.16~exp12ubuntu10.10UNKNOWN
Rows per page:
1-10 of 181

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

32.4%