[Touch-packages] [Bug 1647467] Re: InRelease file splitter treats getline() errors as EOF

2019-01-29 Thread A. Denton
> It allows for attacking a repository via MITM attacks, circumventing the signature of the InRelease file. > ("deb http://192.168.0.2:1337/debian/ jessie-updates main" or so). [..] This simulates a MITM attack or compromised mirror. That sounds like it matters, where that InRelease file comes

[Touch-packages] [Bug 1647467] Re: InRelease file splitter treats getline() errors as EOF

2017-01-10 Thread Julian Andres Klode
** Tags added: verification-done -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apt in Ubuntu. https://bugs.launchpad.net/bugs/1647467 Title: InRelease file splitter treats getline() errors as EOF Status in apt package

[Touch-packages] [Bug 1647467] Re: InRelease file splitter treats getline() errors as EOF

2016-12-17 Thread Launchpad Bug Tracker
This bug was fixed in the package apt - 1.4~beta2 --- apt (1.4~beta2) unstable; urgency=high [ John R. Lenton ] * bash-completion: Only complete understood file paths for install (LP: #1645815) [ Julian Andres Klode ] * SECURITY UPDATE: gpgv: Check for errors when

[Touch-packages] [Bug 1647467] Re: InRelease file splitter treats getline() errors as EOF

2016-12-13 Thread Ubuntu Foundations Team Bug Bot
** Tags added: patch -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apt in Ubuntu. https://bugs.launchpad.net/bugs/1647467 Title: InRelease file splitter treats getline() errors as EOF Status in apt package in Ubuntu:

[Touch-packages] [Bug 1647467] Re: InRelease file splitter treats getline() errors as EOF

2016-12-13 Thread Tyler Hicks
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apt in Ubuntu. https://bugs.launchpad.net/bugs/1647467 Title: InRelease file splitter treats getline()

[Touch-packages] [Bug 1647467] Re: InRelease file splitter treats getline() errors as EOF

2016-12-13 Thread Launchpad Bug Tracker
This bug was fixed in the package apt - 1.0.1ubuntu2.17 --- apt (1.0.1ubuntu2.17) trusty-security; urgency=high * SECURITY UPDATE: gpgv: Check for errors when splitting files (CVE-2016-1252) Thanks to Jann Horn, Google Project Zero for reporting the issue (LP: #1647467)