Low severity3.7NVD Advisory· Published Nov 26, 2019· Updated Jun 16, 2026
CVE-2011-3374
CVE-2011-3374
Description
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- cpe:2.3:a:debian:advanced_package_tool:*:*:*:*:*:*:*:*
- apt/aptv5Range: All versions
Patches
Vulnerability mechanics
References
7- seclists.org/fulldisclosure/2011/Sep/221nvdExploitMailing ListThird Party Advisory
- bugs.debian.org/cgi-bin/bugreport.cginvdIssue TrackingMailing ListThird Party Advisory
- people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-3374.htmlnvdThird Party Advisory
- security-tracker.debian.org/tracker/CVE-2011-3374nvdThird Party Advisory
- ubuntu.com/security/CVE-2011-3374nvdThird Party Advisory
- access.redhat.com/security/cve/cve-2011-3374nvdBroken Link
- snyk.io/vuln/SNYK-LINUX-APT-116518nvdBroken Link
News mentions
0No linked articles in our index yet.