CVE-2018-0501

CWE-3476 documents6 sources
Severity
5.9MEDIUM
EPSS
0.1%
top 67.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 21
Latest updateMay 14

Description

The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verification for the InRelease file of a fallback mirror, aka mirrorfail.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages3 packages

NVDdebian/advanced_package_tool1.6.01.6.4+1
CVEListV5apt_1.6.x_before_1.6.4_and_1.7.x_before_1.7.0~alpha3APT 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3
Debianapt< 1.6.4+3

Also affects: Ubuntu Linux 18.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-h75r-32pp-3c7j: The mirror:// method implementation in Advanced Package Tool (APT) 12022-05-14
OSV
CVE-2018-0501: The mirror:// method implementation in Advanced Package Tool (APT) 12018-08-21
CVEList
CVE-2018-0501: The mirror:// method implementation in Advanced Package Tool (APT) 12018-08-21

📋Vendor Advisories

2
Ubuntu
APT vulnerability2018-08-20
Debian
CVE-2018-0501: apt - The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before ...2018