CVE-2011-4407
EPSS 0.63%
描述
ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.
如何修補 CVE-2011-4407
要修補 CVE-2011-4407,請將受影響套件升級到下列已修補版本。
- Debian/software-properties—升級至 0.76.7debian2+nmu2 或更新版本
CVE-2011-4407 正在被利用嗎?
低 — EPSS 為 0.6%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 0.76.7debian2+nmu2