CVE-2018-0501
21.08.2018, 00:29
The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verification for the InRelease file of a fallback mirror, aka mirrorfail.Enginsight
Vendor | Product | Version |
---|---|---|
canonical | ubuntu_linux | 18.04 |
debian | advanced_package_tool | 1.6.0 ≤ 𝑥 < 1.6.4 |
debian | advanced_package_tool | 1.7.0:alpha |
debian | advanced_package_tool | 1.7.0:alpha1 |
debian | advanced_package_tool | 1.7.0:alpha2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References