CVE-2011-1829
published 2011-07-27CVE-2011-1829: APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.69%
74.5th percentile
APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | advanced_package_tool | < 0.8.15.2 | 0.8.15.2 |
| debian | apt | < apt 0.8.15.2 (bookworm) | apt 0.8.15.2 (bookworm) |
| debian | apt | >= 0 < 0.8.15.2 | 0.8.15.2 |
| debian | apt | >= 0 < 0.8.15.2 | 0.8.15.2 |
| debian | apt | >= 0 < 0.8.15.2 | 0.8.15.2 |
| debian | apt | >= 0 < 0.8.15.2 | 0.8.15.2 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
APT vulnerability
vendor_ubuntu·2011-07-13
CVE-2011-1829 APT vulnerability
Title: APT vulnerability
Summary: An attacker could trick APT into installing altered packages.
William Grant discovered that APT incorrectly validated inline GPG
signatures. If a remote attacker were able to perform a machine-in-the-middle
attack, this flaw could potentially be used to install altered packages.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2011-1829: apt - APT before 0.8.15.2 does not properly validate inline GPG signatures, which allo...
vendor_debian·2011·CVSS 4.3
CVE-2011-1829 [MEDIUM] CVE-2011-1829: apt - APT before 0.8.15.2 does not properly validate inline GPG signatures, which allo...
APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.
Scope: local
bookworm: resolved (fixed in 0.8.15.2)
bullseye: resolved (fixed in 0.8.15.2)
forky: resolved (fixed in 0.8.15.2)
sid: resolved (fixed in 0.8.15.2)
trixie: resolved (fixed in 0.8.15.2)
GHSA
GHSA-qq54-xq37-2h5v: APT before 0
ghsa_unreviewed·2022-05-13
CVE-2011-1829 [MEDIUM] CWE-20 GHSA-qq54-xq37-2h5v: APT before 0
APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.
OSV
CVE-2011-1829: APT before 0
osv·2011-07-27·CVSS 4.3
CVE-2011-1829 [MEDIUM] CVE-2011-1829: APT before 0
APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://launchpadlibrarian.net/75126628/apt_0.8.13.2ubuntu2_0.8.13.2ubuntu4.1.diff.gzhttp://packages.debian.org/changelogs/pool/main/a/apt/current/changeloghttp://www.securityfocus.com/bid/48671http://www.ubuntu.com/usn/USN-1169-1https://exchange.xforce.ibmcloud.com/vulnerabilities/68560https://launchpad.net/bugs/784473https://launchpad.net/ubuntu/+archive/primary/+sourcepub/1817196/+listing-archive-extrahttp://launchpadlibrarian.net/75126628/apt_0.8.13.2ubuntu2_0.8.13.2ubuntu4.1.diff.gzhttp://packages.debian.org/changelogs/pool/main/a/apt/current/changeloghttp://www.securityfocus.com/bid/48671http://www.ubuntu.com/usn/USN-1169-1https://exchange.xforce.ibmcloud.com/vulnerabilities/68560https://launchpad.net/bugs/784473https://launchpad.net/ubuntu/+archive/primary/+sourcepub/1817196/+listing-archive-extra
2011-07-27
Published