CVE-2012-0944

NameCVE-2012-0944
DescriptionAptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is not simulated, which allows remote attackers to install arbitrary packages via a man-in-the-middle attack.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
aptdaemonsourcesqueeze(not affected)
aptdaemonsource(unstable)0.43+bzr790-1

Notes

[squeeze] - aptdaemon <not-affected> (Vulnerable code not present)

Search for package or bug name: Reporting problems