CVE-2009-1358
published 2009-04-21CVE-2009-1358: apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed…
PriorityP344critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.40%
90.2th percentile
apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.
Affected
170 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | advanced_package_tool | <= 0.7.20 | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | advanced_package_tool | — | — |
| debian | apt | < apt 0.7.21 (bookworm) | apt 0.7.21 (bookworm) |
| debian | apt | — | — |
| debian | apt | — | — |
| debian | apt | — | — |
| debian | apt | — | — |
| debian | apt | — | — |
| debian | apt | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2009-1358: apt - apt-get in apt before 0.7.21 does not check for the correct error code from gpgv...
vendor_debian·2009·CVSS 10.0
CVE-2009-1358 [CRITICAL] CVE-2009-1358: apt - apt-get in apt before 0.7.21 does not check for the correct error code from gpgv...
apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.
Scope: local
bookworm: resolved (fixed in 0.7.21)
bullseye: resolved (fixed in 0.7.21)
forky: resolved (fixed in 0.7.21)
sid: resolved (fixed in 0.7.21)
trixie: resolved (fixed in 0.7.21)
Red Hat
apt: incorrect gpg exit status checking when verifying repository signature
vendor_redhat·CVSS 10.0
CVE-2009-1358 [CRITICAL] apt: incorrect gpg exit status checking when verifying repository signature
apt: incorrect gpg exit status checking when verifying repository signature
apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.
GHSA
GHSA-ggxf-mg5q-59fp: apt-get in apt before 0
ghsa_unreviewed·2022-05-02
CVE-2009-1358 [HIGH] GHSA-ggxf-mg5q-59fp: apt-get in apt before 0
apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.
OSV
CVE-2009-1358: apt-get in apt before 0
osv·2009-04-21·CVSS 10.0
CVE-2009-1358 [CRITICAL] CVE-2009-1358: apt-get in apt before 0
apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.
No detection rules found.
No public exploits indexed.
CWE
Improper Check for Certificate Revocation
mitre_cwe
CWE-299 Improper Check for Certificate Revocation
CWE-299: Improper Check for Certificate Revocation
The product does not check or incorrectly checks the revocation status of a certificate, which may cause it to use a certificate that has been compromised.
An improper check for certificate revocation is a far more serious flaw than related certificate failures. This is because the use of any revoked certificate is almost certainly malicious. The most common reason for certificate revocation is compromise of the system in question, with the result that no legitimate servers will be using a revoked certificate, unless they are sorely out of sync.
Modes of Introduction:
Phase: Implementation
Note: When the product uses certificate pinning, the developer might not properly validate all relevant components of the certificate before pinning
CWE
Improper Certificate Validation
mitre_cwe
CWE-295 Improper Certificate Validation
CWE-295: Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
Background: A certificate is a token that associates an identity (principal) to a cryptographic key. Certificates can be used to check if a public key belongs to the assumed owner.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Phase: Implementation
Note: When the product uses certificate pinning, the developer might not properly validate all relevant components of the certificate before pinning the certificate. This can make it difficult or expensive to test after the pinning is complete.
Common Consequences:
Scope: Integrity, Authentication. Im
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=433091http://secunia.com/advisories/34829http://secunia.com/advisories/34832http://secunia.com/advisories/34874http://www.debian.org/security/2009/dsa-1779http://www.securityfocus.com/bid/34630https://bugs.launchpad.net/ubuntu/+source/apt/+bug/356012https://exchange.xforce.ibmcloud.com/vulnerabilities/50086https://usn.ubuntu.com/762-1/http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=433091http://secunia.com/advisories/34829http://secunia.com/advisories/34832http://secunia.com/advisories/34874http://www.debian.org/security/2009/dsa-1779http://www.securityfocus.com/bid/34630https://bugs.launchpad.net/ubuntu/+source/apt/+bug/356012https://exchange.xforce.ibmcloud.com/vulnerabilities/50086https://usn.ubuntu.com/762-1/
2009-04-21
Published