CVE-2013-1051
published 2013-03-21CVE-2013-1051: apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle attackers to modify packages before…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.34%
68.2th percentile
apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle attackers to modify packages before installation via unknown vectors, possibly related to integrity checking and the use of third-party repositories.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | advanced_package_tool | — | — |
| debian | apt | < apt 0.9.7.8 (bookworm) | apt 0.9.7.8 (bookworm) |
| debian | apt | — | — |
| debian | apt | >= 0 < 0.9.7.8 | 0.9.7.8 |
| debian | apt | >= 0 < 0.9.7.8 | 0.9.7.8 |
| debian | apt | >= 0 < 0.9.7.8 | 0.9.7.8 |
| debian | apt | >= 0 < 0.9.7.8 | 0.9.7.8 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
APT vulnerability
vendor_ubuntu·2013-03-14
CVE-2013-1051 APT vulnerability
Title: APT vulnerability
Summary: An attacker could trick APT into installing altered packages.
Ansgar Burchardt discovered that APT incorrectly handled InRelease files.
If a remote attacker were able to perform a machine-in-the-middle attack, this
flaw could potentially be used to install altered packages.
This update corrects the issue by disabling InRelease file support
completely. Please note that this update breaks third-party repositories
that provide only a InRelease file and no separate Release and Release.gpg
files. The default Ubuntu repositories do not use InRelease files.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2013-1051: apt - apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InReleas...
vendor_debian·2013·CVSS 4.3
CVE-2013-1051 [MEDIUM] CVE-2013-1051: apt - apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InReleas...
apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle attackers to modify packages before installation via unknown vectors, possibly related to integrity checking and the use of third-party repositories.
Scope: local
bookworm: resolved (fixed in 0.9.7.8)
bullseye: resolved (fixed in 0.9.7.8)
forky: resolved (fixed in 0.9.7.8)
sid: resolved (fixed in 0.9.7.8)
trixie: resolved (fixed in 0.9.7.8)
GHSA
GHSA-pgxw-xqx6-crgv: apt 0
ghsa_unreviewed·2022-05-13
CVE-2013-1051 [MEDIUM] CWE-20 GHSA-pgxw-xqx6-crgv: apt 0
apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle attackers to modify packages before installation via unknown vectors, possibly related to integrity checking and the use of third-party repositories.
OSV
CVE-2013-1051: apt 0
osv·2013-03-21·CVSS 4.3
CVE-2013-1051 [MEDIUM] CVE-2013-1051: apt 0
apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle attackers to modify packages before installation via unknown vectors, possibly related to integrity checking and the use of third-party repositories.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-03-21
Published