[Bug 856489] [NEW] Improper verification of updated key via apt-key net-update

Jamie Strandboge jamie at ubuntu.com
Thu Sep 22 15:06:15 UTC 2011


*** This bug is a security vulnerability ***

Public security bug reported:

As reported on full-disclosure:
http://seclists.org/fulldisclosure/2011/Sep/221

** Affects: apt (Ubuntu)
     Importance: Critical
     Assignee: Marc Deslauriers (mdeslaur)
         Status: In Progress

** Affects: apt (Ubuntu Lucid)
     Importance: Critical
     Assignee: Marc Deslauriers (mdeslaur)
         Status: In Progress

** Affects: apt (Ubuntu Maverick)
     Importance: Critical
     Assignee: Marc Deslauriers (mdeslaur)
         Status: In Progress

** Affects: apt (Ubuntu Natty)
     Importance: Critical
     Assignee: Marc Deslauriers (mdeslaur)
         Status: In Progress

** Affects: apt (Ubuntu Oneiric)
     Importance: Critical
     Assignee: Marc Deslauriers (mdeslaur)
         Status: In Progress

** This bug has been flagged as a security vulnerability

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to apt in Ubuntu.
https://bugs.launchpad.net/bugs/856489

Title:
  Improper verification of updated key via apt-key net-update

Status in “apt” package in Ubuntu:
  In Progress
Status in “apt” source package in Lucid:
  In Progress
Status in “apt” source package in Maverick:
  In Progress
Status in “apt” source package in Natty:
  In Progress
Status in “apt” source package in Oneiric:
  In Progress

Bug description:
  As reported on full-disclosure:
  http://seclists.org/fulldisclosure/2011/Sep/221

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apt/+bug/856489/+subscriptions




More information about the foundations-bugs mailing list