Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install altered packages via a man-in-the-middle (MITM) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3587.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
APT 安全漏洞
Vulnerability Description
APT 0.7.25之前的0.7.x版本和0.8.16之前的0.8.x版本中存在漏洞。当使用apt-key net-update导入密钥环时,依赖GnuPG自变量顺序并且不检查GPG子键。远程攻击者可利用该漏洞通过中间人(MITM)攻击安装修改的数据包。
CVSS Information
N/A
Vulnerability Type
N/A