CVE-2013-1051

Publication date 14 March 2013

Last updated 24 July 2024


Ubuntu priority

apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle attackers to modify packages before installation via unknown vectors, possibly related to integrity checking and the use of third-party repositories.

Read the notes from the security team

Status

Package Ubuntu Release Status
apt 12.10 quantal
Fixed 0.9.7.5ubuntu5.4
12.04 LTS precise
Fixed 0.8.16~exp12ubuntu10.10
11.10 oneiric
Fixed 0.8.16~exp5ubuntu13.7
10.04 LTS lucid
Not affected
8.04 LTS hardy
Not affected

Notes


mdeslaur

only oneiric+ support InRelease files

References

Related Ubuntu Security Notices (USN)

Other references