[Bug 1013681] [NEW] make apt-key net-update secure
    Jamie Strandboge 
    jamie at ubuntu.com
       
    Fri Jun 15 14:05:05 UTC 2012
    
    
  
*** This bug is a security vulnerability ***
Public security bug reported:
Attacks are being performed against the 'apt-key net-update' command and
it is not considered secure. While it is in the process of being
disabled in Ubuntu, it should be improved to be secure.
References:
https://bugs.launchpad.net/ubuntu/+source/apt/+bug/857472
https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1013128
https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1013639
http://seclists.org/fulldisclosure/2011/Sep/222
http://seclists.org/fulldisclosure/2012/Jun/267
http://seclists.org/fulldisclosure/2012/Jun/271
http://seclists.org/fulldisclosure/2012/Jun/289
** Affects: apt (Ubuntu)
     Importance: High
         Status: Triaged
** Tags: rls-q-incoming
** Visibility changed to: Public
** Changed in: apt (Ubuntu)
   Importance: Undecided => High
** Changed in: apt (Ubuntu)
       Status: New => Triaged
** Tags added: rls-q-incoming
** Summary changed:
- make net-update secure
+ make apt-key net-update secure
-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to apt in Ubuntu.
https://bugs.launchpad.net/bugs/1013681
Title:
  make apt-key net-update secure
Status in “apt” package in Ubuntu:
  Triaged
Bug description:
  Attacks are being performed against the 'apt-key net-update' command
  and it is not considered secure. While it is in the process of being
  disabled in Ubuntu, it should be improved to be secure.
  References:
  https://bugs.launchpad.net/ubuntu/+source/apt/+bug/857472
  https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1013128
  https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1013639
  http://seclists.org/fulldisclosure/2011/Sep/222
  http://seclists.org/fulldisclosure/2012/Jun/267
  http://seclists.org/fulldisclosure/2012/Jun/271
  http://seclists.org/fulldisclosure/2012/Jun/289
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1013681/+subscriptions
    
    
More information about the foundations-bugs
mailing list