Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-1358
HistoryApr 21, 2009 - 12:00 a.m.

CVE-2009-1358

2009-04-2100:00:00
ubuntu.com
ubuntu.com
16

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.023

Percentile

89.7%

apt-get in apt before 0.7.21 does not check for the correct error code from
gpgv, which causes apt to treat a repository as valid even when it has been
signed with a key that has been revoked or expired, which might allow
remote attackers to trick apt into installing malicious repositories.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchapt< 0.6.43.3ubuntu3.1UNKNOWN
ubuntu8.04noarchapt< 0.7.9ubuntu17.2UNKNOWN
ubuntu8.10noarchapt< 0.7.14ubuntu6.1UNKNOWN

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.023

Percentile

89.7%