CVE-2019-11480

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
14/04/2020
Last modified:
14/04/2020

Description

The pc-kernel snap build process hardcoded the --allow-insecure-repositories and --allow-unauthenticated apt options when creating the build chroot environment. This could allow an attacker who is able to perform a MITM attack between the build environment and the Ubuntu archive to install a malicious package within the build chroot. This issue affects pc-kernel versions prior to and including 2019-07-16

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:canonical:c-kernel:*:*:*:*:*:*:*:* 2019-07-16 (including)