[Bug 1013639] Re: net-update verifcation checking is still insecure (aka gpg key shadowing, again)
Jamie Strandboge
jamie at ubuntu.com
Fri Jun 15 15:20:01 UTC 2012
** Changed in: apt (Ubuntu Lucid)
Status: In Progress => Fix Committed
** Changed in: apt (Ubuntu Natty)
Status: In Progress => Fix Committed
** Changed in: apt (Ubuntu Oneiric)
Status: In Progress => Fix Committed
** Changed in: apt (Ubuntu Precise)
Status: In Progress => Fix Committed
** Changed in: apt (Ubuntu Quantal)
Status: In Progress => Fix Committed
** Changed in: apt (Ubuntu Hardy)
Status: In Progress => Fix Committed
--
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to apt in Ubuntu.
https://bugs.launchpad.net/bugs/1013639
Title:
net-update verifcation checking is still insecure (aka gpg key
shadowing, again)
Status in “apt” package in Ubuntu:
Fix Committed
Status in “apt” source package in Lucid:
Fix Committed
Status in “apt” source package in Natty:
Fix Committed
Status in “apt” source package in Oneiric:
Fix Committed
Status in “apt” source package in Precise:
Fix Committed
Status in “apt” source package in Quantal:
Fix Committed
Status in “apt” source package in Hardy:
Fix Committed
Bug description:
This is related to but different than:
https://bugs.launchpad.net/ubuntu/+source/apt/+bug/857472
https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1013128
FYI:
http://seclists.org/fulldisclosure/2012/Jun/271
http://seclists.org/fulldisclosure/2012/Jun/289
The fix for both of the previous bugs was not enough. There is
reportedly an active exploit utilizing the Ubuntu CD Image Automatic
Signing Key.
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1013639/+subscriptions
More information about the foundations-bugs
mailing list