CVE-2011-1829
27.07.2011, 02:55
APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.Enginsight
Vendor | Product | Version |
---|---|---|
debian | advanced_package_tool | 𝑥 < 0.8.15.2 |
canonical | ubuntu_linux | 11.04 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References