Unrated severityNVD Advisory· Published Jul 27, 2011· Updated Apr 29, 2026
CVE-2011-1829
CVE-2011-1829
Description
APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.
Affected products
2- cpe:2.3:o:canonical:ubuntu_linux:11.04:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- launchpadlibrarian.net/75126628/apt_0.8.13.2ubuntu2_0.8.13.2ubuntu4.1.diff.gznvdPatchThird Party Advisory
- launchpad.net/ubuntu/+archive/primary/+sourcepub/1817196/+listing-archive-extranvdPatch
- packages.debian.org/changelogs/pool/main/a/apt/current/changelognvdRelease NotesVendor Advisory
- www.securityfocus.com/bid/48671nvdThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/USN-1169-1nvdThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/68560nvdThird Party AdvisoryVDB Entry
- launchpad.net/bugs/784473nvdThird Party Advisory
News mentions
0No linked articles in our index yet.