4.3
CVSSv2

CVE-2011-1829

Published: 27/07/2011 Updated: 25/03/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

APT prior to 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle malicious users to install modified packages via vectors involving lack of an initial clearsigned message.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian advanced package tool

canonical ubuntu linux 11.04

Vendor Advisories

An attacker could trick APT into installing altered packages ...