*** This bug is a security vulnerability ***

Public security bug reported:

Attacks are being performed against the 'apt-key net-update' command and
it is not considered secure. While it is in the process of being
disabled in Ubuntu, it should be improved to be secure.

References:
https://bugs.launchpad.net/ubuntu/+source/apt/+bug/857472
https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1013128
https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1013639
http://seclists.org/fulldisclosure/2011/Sep/222
http://seclists.org/fulldisclosure/2012/Jun/267
http://seclists.org/fulldisclosure/2012/Jun/271
http://seclists.org/fulldisclosure/2012/Jun/289

** Affects: apt (Ubuntu)
     Importance: High
         Status: Triaged


** Tags: rls-q-incoming

** Visibility changed to: Public

** Changed in: apt (Ubuntu)
   Importance: Undecided => High

** Changed in: apt (Ubuntu)
       Status: New => Triaged

** Tags added: rls-q-incoming

** Summary changed:

- make net-update secure
+ make apt-key net-update secure

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1013681

Title:
  make apt-key net-update secure

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1013681/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to