CVE-2012-0214 Information
Feb 14, 2021
cve
Description
The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before 0.8.16~exp13 when updating from repositories that use InRelease files allows man-in-the-middle attackers to install arbitrary packages by preventing a user from downloading the new InRelease file which leaves the original InRelease file active and makes it more difficult to detect that the Packages file is modified and unsigned.
Reference
http://anonscm.debian.org/gitweb/?p=apt/apt.git;a=commitdiff;h=b7a6594d1e5ed199a7a472b78b33e070375d6f92 http://anonscm.debian.org/gitweb/?p=apt/apt.git;a=commitdiff;h=de498a528cd6fc36c4bb22bf8dec6558e21cc9b6 http://www.ubuntu.com/usn/USN-1385-1
Share on: