Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 12.04 LTS USN-1475-1 Critical: APT Keyring Validation

ubuntu
Calendar Grey June 15, 2012
Scroller Ubuntu
APT package update in Ubuntu 12.04 LTS enhances keyring validation security against attacks.
APT now more thoroughly verifies imported keyrings.

Summary

APT now more thoroughly verifies imported keyrings.

Software Description:

- apt: Advanced front-end for dpkg

Details:

Georgi Guninski discovered that APT relied on GnuPG argument order and did

not check GPG subkeys when validating imported keyrings via apt-key

net-update. While it appears that a man-in-the-middle attacker cannot

exploit this, as a hardening measure this update adjusts apt-key to

validate all subkeys when checking for key collisions.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  apt                             0.8.16~exp12ubuntu10.1

Ubuntu 11.10:
  apt                             0.8.16~exp5ubuntu13.4

Ubuntu 11.04:
  apt                             0.8.13.2ubuntu4.5

Ubuntu 10.04 LTS:
  apt                             0.7.25.3ubuntu9.12

Ubuntu 8.04 LTS:
  apt                             0.7.9ubuntu17.5

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1475-1

https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1013128

Severity
critical
Lowest
Low
Medium
High
Critical

June 15, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.