CVE-2012-0214

The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before 0.8.16~exp13, when updating from repositories that use InRelease files, allows man-in-the-middle attackers to install arbitrary packages by preventing a user from downloading the new InRelease file, which leaves the original InRelease file active and makes it more difficult to detect that the Packages file is modified and unsigned.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:advanced_package_tool:advanced_package_tool:0.8.12:*:*:*:*:*:*:*
cpe:2.3:a:advanced_package_tool:advanced_package_tool:0.8.13:*:*:*:*:*:*:*
cpe:2.3:a:advanced_package_tool:advanced_package_tool:0.8.14:*:*:*:*:*:*:*
cpe:2.3:a:advanced_package_tool:advanced_package_tool:0.8.15:*:*:*:*:*:*:*
cpe:2.3:a:advanced_package_tool:advanced_package_tool:*:*:*:*:*:*:*:*
cpe:2.3:a:advanced_package_tool:advanced_package_tool:0.8.11:*:*:*:*:*:*:*

Information

Published : 2014-04-15 16:55

Updated : 2014-04-16 08:13


NVD link : CVE-2012-0214

Mitre link : CVE-2012-0214


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

advanced_package_tool

  • advanced_package_tool