[Bug 1329274] Re: apt-get source fails to warn on unauthenticated packages
Marc Deslauriers
marc.deslauriers at canonical.com
Fri Jun 13 16:58:36 UTC 2014
** Changed in: apt (Ubuntu Lucid)
Assignee: (unassigned) => Marc Deslauriers (mdeslaur)
** Changed in: apt (Ubuntu Precise)
Assignee: (unassigned) => Marc Deslauriers (mdeslaur)
** Changed in: apt (Ubuntu Saucy)
Assignee: (unassigned) => Marc Deslauriers (mdeslaur)
** Changed in: apt (Ubuntu Trusty)
Assignee: (unassigned) => Marc Deslauriers (mdeslaur)
** Changed in: apt (Ubuntu Lucid)
Status: New => Confirmed
** Changed in: apt (Ubuntu Lucid)
Importance: Undecided => Medium
** Changed in: apt (Ubuntu Precise)
Status: New => Confirmed
** Changed in: apt (Ubuntu Precise)
Importance: Undecided => Medium
** Changed in: apt (Ubuntu Saucy)
Status: New => Confirmed
** Changed in: apt (Ubuntu Saucy)
Importance: Undecided => Medium
** Changed in: apt (Ubuntu Trusty)
Status: New => Confirmed
** Changed in: apt (Ubuntu Trusty)
Importance: Undecided => Medium
--
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to apt in Ubuntu.
https://bugs.launchpad.net/bugs/1329274
Title:
apt-get source fails to warn on unauthenticated packages
Status in APT:
Fix Released
Status in “apt” package in Ubuntu:
In Progress
Status in “apt” source package in Lucid:
Confirmed
Status in “apt” source package in Precise:
Confirmed
Status in “apt” source package in Saucy:
Confirmed
Status in “apt” source package in Trusty:
Confirmed
Status in “apt” source package in Utopic:
In Progress
Bug description:
apt-get source foo will not warn if the repository that foo belongs to
has no signature attached.
It should fails in this case - this is CVE-2014-0478
To manage notifications about this bug go to:
https://bugs.launchpad.net/apt/+bug/1329274/+subscriptions
More information about the foundations-bugs
mailing list