Unrated severityNVD Advisory· Published Mar 21, 2013· Updated Apr 29, 2026
CVE-2013-1051
CVE-2013-1051
Description
apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle attackers to modify packages before installation via unknown vectors, possibly related to integrity checking and the use of third-party repositories.
Affected products
5- cpe:2.3:a:debian:advanced_package_tool:0.8.16:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- secunia.com/advisories/52633nvdVendor Advisory
- osvdb.org/91428nvd
- www.ubuntu.com/usn/USN-1762-1nvd
News mentions
0No linked articles in our index yet.