CVE-2009-1358

Publication date 21 April 2009

Last updated 24 July 2024


Ubuntu priority

Description

apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.

Status

Package Ubuntu Release Status
apt 8.10 intrepid
Fixed 0.7.14ubuntu6.1
8.04 LTS hardy
Fixed 0.7.9ubuntu17.2
6.06 LTS dapper
Fixed 0.6.43.3ubuntu3.1

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
apt