CVE-2011-1829

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
27/07/2011
Last modified:
11/04/2025

Description

APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:debian:advanced_package_tool:*:*:*:*:*:*:*:* 0.8.15.2 (excluding)
cpe:2.3:o:canonical:ubuntu_linux:11.04:*:*:*:*:*:*:*