CVE-2013-1051

NameCVE-2013-1051
Descriptionapt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle attackers to modify packages before installation via unknown vectors, possibly related to integrity checking and the use of third-party repositories.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apt (PTS)stretch1.4.10fixed
stretch (security)1.4.11fixed
buster1.8.2.3fixed
buster (security)1.8.2.2fixed
bullseye2.2.4fixed
bookworm, sid2.5.0fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
aptsourcesqueeze(not affected)
aptsource(unstable)0.9.7.8

Notes

[squeeze] - apt <not-affected> (InRelease support not used)

Search for package or bug name: Reporting problems