apt-get source fails to warn on unauthenticated packages
Bug #1329274 reported by
Michael Vogt
This bug affects 2 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
APT |
Fix Released
|
Unknown
|
|||
apt (Ubuntu) |
Fix Released
|
High
|
Michael Vogt | ||
Lucid |
Fix Released
|
Medium
|
Marc Deslauriers | ||
Precise |
Fix Released
|
Medium
|
Marc Deslauriers | ||
Saucy |
Fix Released
|
Medium
|
Marc Deslauriers | ||
Trusty |
Fix Released
|
Medium
|
Marc Deslauriers | ||
Utopic |
Fix Released
|
High
|
Michael Vogt |
Bug Description
apt-get source foo will not warn if the repository that foo belongs to has no signature attached.
It should fails in this case - this is CVE-2014-0478
Changed in apt (Ubuntu): | |
importance: | Undecided → High |
assignee: | nobody → Michael Vogt (mvo) |
status: | New → In Progress |
information type: | Public → Public Security |
description: | updated |
Changed in apt: | |
status: | Unknown → New |
tags: | added: patch |
Changed in apt: | |
status: | New → Fix Released |
Changed in apt (Ubuntu Lucid): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in apt (Ubuntu Precise): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in apt (Ubuntu Saucy): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in apt (Ubuntu Trusty): | |
assignee: | nobody → Marc Deslauriers (mdeslaur) |
Changed in apt (Ubuntu Lucid): | |
status: | New → Confirmed |
importance: | Undecided → Medium |
Changed in apt (Ubuntu Precise): | |
status: | New → Confirmed |
importance: | Undecided → Medium |
Changed in apt (Ubuntu Saucy): | |
status: | New → Confirmed |
importance: | Undecided → Medium |
Changed in apt (Ubuntu Trusty): | |
status: | New → Confirmed |
importance: | Undecided → Medium |
Changed in apt (Ubuntu Utopic): | |
status: | In Progress → Fix Released |
To post a comment you must log in.
This bug was fixed in the package apt - 0.9.9.1~ubuntu3.2
---------------
apt (0.9.9.1~ubuntu3.2) saucy-security; urgency=low
* SECURITY UPDATE: incorrect apt-get source validation (LP: #1329274) n/test- apt-get- source- authenticated, integration/ framework.
- warn if not authenticated in cmdline/apt-get.cc, added regression
test to test/integratio
test/
- CVE-2014-0478
-- Michael Vogt <email address hidden> Thu, 12 Jun 2014 14:02:26 +0200