Improper Verification of Cryptographic Signature
Affecting apt package, versions *
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.
References
CVSS Score
3.7
low severity
-
Attack VectorNetwork
-
Attack ComplexityHigh
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityLow
-
AvailabilityNone
- CVE
- CVE-2011-3374
- CWE
- CWE-347
- Snyk ID
- SNYK-DEBIAN10-APT-407502
- Disclosed
- 26 Nov, 2019
- Published
- 27 Jun, 2018