CVE-2013-1051

NameCVE-2013-1051
Descriptionapt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle attackers to modify packages before installation via unknown vectors, possibly related to integrity checking and the use of third-party repositories.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apt (PTS)bullseye2.2.4fixed
bookworm2.6.1fixed
trixie2.9.10fixed
sid2.9.13fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
aptsourcesqueeze(not affected)
aptsource(unstable)0.9.7.8

Notes

[squeeze] - apt <not-affected> (InRelease support not used)

Search for package or bug name: Reporting problems