4.3
CVSSv2

CVE-2013-1051

Published: 21/03/2013 Updated: 08/01/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle malicious users to modify packages before installation via unknown vectors, possibly related to integrity checking and the use of third-party repositories.

Vulnerable Product Search on Vulmon Subscribe to Product

debian advanced package tool 0.8.16

debian apt 0.9.7

canonical ubuntu linux 11.10

canonical ubuntu linux 12.04

canonical ubuntu linux 12.10

Vendor Advisories

An attacker could trick APT into installing altered packages ...