CVE-2012-0214
EPSS 0.12%發布日:2014/4/15修改日:2026/4/28
也稱為:DEBIAN-CVE-2012-0214
描述
The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before 0.8.16~exp13, when updating from repositories that use InRelease files, allows man-in-the-middle attackers to install arbitrary packages by preventing a user from downloading the new InRelease file, which leaves the original InRelease file active and makes it more difficult to detect that the Packages file is modified and unsigned.
受影響套件(1)
- Debian/aptfrom 0, < 0.8.15.10