Affected applications were rebuilt against version 0.10.60 of the the `openssl` crate (the Rust bindings for OpenSSL) to address two security advisories: - https://rustsec.org/advisories/RUSTSEC-2023-0044.html - https://rustsec.org/advisories/RUSTSEC-2023-0072.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-6215ea423b 2023-12-06 01:45:51.746952 -------------------------------------------------------------------------------- Name : keyring-ima-signer Product : Fedora 38 Version : 0.1.0 Release : 11.fc38 URL : https://github.com/fedora-iot/keyring-ima-signer/ Summary : An IMA file signing tool using the kernel keyring Description : The IMA (Integrity Measurement Architecture) is a key component of the Linux integrity subsystem designed to ensure integrity, authenticity, and confidentiality of systems including hardware root of trusts (TPM). This tool allows signing of files in userspace, inclusding options of including the signature in xattr or a .sig file, using signing keys stored in the kernel keyring to ensure they're not recoverable. -------------------------------------------------------------------------------- Update Information: Affected applications were rebuilt against version 0.10.60 of the the `openssl` crate (the Rust bindings for OpenSSL) to address two security advisories: - https://rustsec.org/advisories/RUSTSEC-2023-0044.html - https://rustsec.org/advisories/RUSTSEC-2023-0072.html -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 1 2023 Fabio Valentini - 0.1.0-11 - Rebuild for openssl crate > = v0.10.60 (RUSTSEC-2023-0044, RUSTSEC-2023-0072) * Thu Jul 20 2023 Fedora Release Engineering - 0.1.0-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf"update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-6215ea423b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Affected applications were rebuilt against version 0.10.60 of the the `openssl` crate (the Rust bindings for OpenSSL) to address two security advisories: - https://rustsec.org/advisories/RUSTSEC-2023-0044.html - https://rustsec.org/advisories/RUSTSEC-2023-0072.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-9790b327cb 2023-12-06 01:39:35.067298 -------------------------------------------------------------------------------- Name : keyring-ima-signer Product : Fedora 39 Version : 0.1.0 Release : 11.fc39 URL : https://github.com/fedora-iot/keyring-ima-signer/ Summary : An IMA file signing tool using the kernel keyring Description : The IMA (Integrity Measurement Architecture) is a key component of the Linux integrity subsystem designed to ensure integrity, authenticity, and confidentiality of systems including hardware root of trusts (TPM). This tool allows signing of files in userspace, inclusding options of including the signature in xattr or a .sig file, using signing keys stored in the kernel keyring to ensure they're not recoverable. -------------------------------------------------------------------------------- Update Information: Affected applications were rebuilt against version 0.10.60 of the the `openssl` crate (the Rust bindings for OpenSSL) to address two security advisories: - https://rustsec.org/advisories/RUSTSEC-2023-0044.html - https://rustsec.org/advisories/RUSTSEC-2023-0072.html -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 1 2023 Fabio Valentini - 0.1.0-11 - Rebuild for openssl crate > = v0.10.60 (RUSTSEC-2023-0044, RUSTSEC-2023-0072) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-9790b327cb' at the command line. For more information, refer tothe dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
debian-archive-keyring is a package containing GnuPG archive keys of the Debian archive. New GPG-keys are being constantly added with every new Debian release. For Debian 10 buster, GPG-keys for 12/bullseye Debian release are added . -------------------------------------------------------------------------Debian LTS Advisory DLA-3482-1
Updated kernel packages that fix one security issue are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Important security impact. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security update Advisory ID: RHSA-2016:0064-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:0064.html Issue date: 2016-01-25 CVE Names: CVE-2016-0728 ==================================================================== 1. Summary: Updated kernel packages that fix one security issue are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. * A use-after-free flaw was found in the way the Linux kernel's key management subsystem handled keyring object reference counting in certain error path of the join_session_keyring() function. A local, unprivileged user could use this flaw to escalate their privileges on thesystem. (CVE-2016-0728, Important) Red Hat would like to thank the Perception Point research team for reporting this issue. All kernel users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. The system must be rebooted for this update to take effect. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1297475 - CVE-2016-0728 kernel: Possible use-after-free vulnerability in keyring facility 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: kernel-3.10.0-327.4.5.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-327.4.5.el7.noarch.rpm kernel-doc-3.10.0-327.4.5.el7.noarch.rpm x86_64: kernel-3.10.0-327.4.5.el7.x86_64.rpm kernel-debug-3.10.0-327.4.5.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-debug-devel-3.10.0-327.4.5.el7.x86_64.rpm kernel-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-327.4.5.el7.x86_64.rpm kernel-devel-3.10.0-327.4.5.el7.x86_64.rpm kernel-headers-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-libs-3.10.0-327.4.5.el7.x86_64.rpm perf-3.10.0-327.4.5.el7.x86_64.rpm perf-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm python-perf-3.10.0-327.4.5.el7.x86_64.rpm python-perf-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: kernel-debug-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-327.4.5.el7.x86_64.rpm perf-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm python-perf-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v.7): Source: kernel-3.10.0-327.4.5.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-327.4.5.el7.noarch.rpm kernel-doc-3.10.0-327.4.5.el7.noarch.rpm x86_64: kernel-3.10.0-327.4.5.el7.x86_64.rpm kernel-debug-3.10.0-327.4.5.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-debug-devel-3.10.0-327.4.5.el7.x86_64.rpm kernel-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-327.4.5.el7.x86_64.rpm kernel-devel-3.10.0-327.4.5.el7.x86_64.rpm kernel-headers-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-libs-3.10.0-327.4.5.el7.x86_64.rpm perf-3.10.0-327.4.5.el7.x86_64.rpm perf-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm python-perf-3.10.0-327.4.5.el7.x86_64.rpm python-perf-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: kernel-debug-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-327.4.5.el7.x86_64.rpm perf-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm python-perf-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: kernel-3.10.0-327.4.5.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-327.4.5.el7.noarch.rpm kernel-doc-3.10.0-327.4.5.el7.noarch.rpm ppc64: kernel-3.10.0-327.4.5.el7.ppc64.rpm kernel-bootwrapper-3.10.0-327.4.5.el7.ppc64.rpm kernel-debug-3.10.0-327.4.5.el7.ppc64.rpm kernel-debug-debuginfo-3.10.0-327.4.5.el7.ppc64.rpm kernel-debug-devel-3.10.0-327.4.5.el7.ppc64.rpm kernel-debuginfo-3.10.0-327.4.5.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-327.4.5.el7.ppc64.rpm kernel-devel-3.10.0-327.4.5.el7.ppc64.rpm kernel-headers-3.10.0-327.4.5.el7.ppc64.rpm kernel-tools-3.10.0-327.4.5.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-327.4.5.el7.ppc64.rpm kernel-tools-libs-3.10.0-327.4.5.el7.ppc64.rpm perf-3.10.0-327.4.5.el7.ppc64.rpm perf-debuginfo-3.10.0-327.4.5.el7.ppc64.rpm python-perf-3.10.0-327.4.5.el7.ppc64.rpm python-perf-debuginfo-3.10.0-327.4.5.el7.ppc64.rpm ppc64le: kernel-3.10.0-327.4.5.el7.ppc64le.rpm kernel-bootwrapper-3.10.0-327.4.5.el7.ppc64le.rpm kernel-debug-3.10.0-327.4.5.el7.ppc64le.rpm kernel-debug-debuginfo-3.10.0-327.4.5.el7.ppc64le.rpm kernel-debuginfo-3.10.0-327.4.5.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-327.4.5.el7.ppc64le.rpm kernel-devel-3.10.0-327.4.5.el7.ppc64le.rpm kernel-headers-3.10.0-327.4.5.el7.ppc64le.rpm kernel-tools-3.10.0-327.4.5.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-327.4.5.el7.ppc64le.rpm kernel-tools-libs-3.10.0-327.4.5.el7.ppc64le.rpm perf-3.10.0-327.4.5.el7.ppc64le.rpm perf-debuginfo-3.10.0-327.4.5.el7.ppc64le.rpm python-perf-3.10.0-327.4.5.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-327.4.5.el7.ppc64le.rpm s390x: kernel-3.10.0-327.4.5.el7.s390x.rpm kernel-debug-3.10.0-327.4.5.el7.s390x.rpm kernel-debug-debuginfo-3.10.0-327.4.5.el7.s390x.rpm kernel-debug-devel-3.10.0-327.4.5.el7.s390x.rpm kernel-debuginfo-3.10.0-327.4.5.el7.s390x.rpm kernel-debuginfo-common-s390x-3.10.0-327.4.5.el7.s390x.rpm kernel-devel-3.10.0-327.4.5.el7.s390x.rpm kernel-headers-3.10.0-327.4.5.el7.s390x.rpm kernel-kdump-3.10.0-327.4.5.el7.s390x.rpm kernel-kdump-debuginfo-3.10.0-327.4.5.el7.s390x.rpm kernel-kdump-devel-3.10.0-327.4.5.el7.s390x.rpm perf-3.10.0-327.4.5.el7.s390x.rpm perf-debuginfo-3.10.0-327.4.5.el7.s390x.rpm python-perf-3.10.0-327.4.5.el7.s390x.rpm python-perf-debuginfo-3.10.0-327.4.5.el7.s390x.rpm x86_64: kernel-3.10.0-327.4.5.el7.x86_64.rpm kernel-debug-3.10.0-327.4.5.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-debug-devel-3.10.0-327.4.5.el7.x86_64.rpm kernel-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-327.4.5.el7.x86_64.rpm kernel-devel-3.10.0-327.4.5.el7.x86_64.rpm kernel-headers-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-libs-3.10.0-327.4.5.el7.x86_64.rpm perf-3.10.0-327.4.5.el7.x86_64.rpm perf-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm python-perf-3.10.0-327.4.5.el7.x86_64.rpm python-perf-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): ppc64: kernel-debug-debuginfo-3.10.0-327.4.5.el7.ppc64.rpm kernel-debuginfo-3.10.0-327.4.5.el7.ppc64.rpm kernel-debuginfo-common-ppc64-3.10.0-327.4.5.el7.ppc64.rpm kernel-tools-debuginfo-3.10.0-327.4.5.el7.ppc64.rpm kernel-tools-libs-devel-3.10.0-327.4.5.el7.ppc64.rpm perf-debuginfo-3.10.0-327.4.5.el7.ppc64.rpm python-perf-debuginfo-3.10.0-327.4.5.el7.ppc64.rpm ppc64le: kernel-debug-debuginfo-3.10.0-327.4.5.el7.ppc64le.rpm kernel-debug-devel-3.10.0-327.4.5.el7.ppc64le.rpm kernel-debuginfo-3.10.0-327.4.5.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-327.4.5.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-327.4.5.el7.ppc64le.rpm kernel-tools-libs-devel-3.10.0-327.4.5.el7.ppc64le.rpm perf-debuginfo-3.10.0-327.4.5.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-327.4.5.el7.ppc64le.rpm x86_64: kernel-debug-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-327.4.5.el7.x86_64.rpm perf-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm python-perf-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm Red Hat Enterprise Linux Workstation (v.7): Source: kernel-3.10.0-327.4.5.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-327.4.5.el7.noarch.rpm kernel-doc-3.10.0-327.4.5.el7.noarch.rpm x86_64: kernel-3.10.0-327.4.5.el7.x86_64.rpm kernel-debug-3.10.0-327.4.5.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-debug-devel-3.10.0-327.4.5.el7.x86_64.rpm kernel-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-327.4.5.el7.x86_64.rpm kernel-devel-3.10.0-327.4.5.el7.x86_64.rpm kernel-headers-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-libs-3.10.0-327.4.5.el7.x86_64.rpm perf-3.10.0-327.4.5.el7.x86_64.rpm perf-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm python-perf-3.10.0-327.4.5.el7.x86_64.rpm python-perf-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: kernel-debug-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-327.4.5.el7.x86_64.rpm perf-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm python-perf-debuginfo-3.10.0-327.4.5.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2016-0728 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFWpnjKXlSAg2UNWIIRAjX2AJ0Zly920KYhKbeQhiNYzJ6h7v0ahACfad0e 2SoGe3rqFq6mU53hqRW5MYk=mvQ5 -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
GnuPG could be made to corrupt the keyring if it imported a specially crafted key.. =========================================================================Ubuntu Security Notice USN-1682-1 January 09, 2013 gnupg, gnupg2 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.10 - Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 10.04 LTS - Ubuntu 8.04 LTS Summary: GnuPG could be made to corrupt the keyring if it imported a specially crafted key. Software Description: - gnupg: GNU privacy guard - a free PGP replacement - gnupg2: GNU privacy guard - a free PGP replacement Details: KB Sriram discovered that GnuPG incorrectly handled certain malformed keys. If a user or automated system were tricked into importing a malformed key, the GnuPG keyring could become corrupted. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: gnupg 1.4.11-3ubuntu4.1 gnupg2 2.0.17-2ubuntu3.1 Ubuntu 12.04 LTS: gnupg 1.4.11-3ubuntu2.2 gnupg2 2.0.17-2ubuntu2.12.04.2 Ubuntu 11.10: gnupg 1.4.11-3ubuntu1.11.10.2 gnupg2 2.0.17-2ubuntu2.11.10.2 Ubuntu 10.04 LTS: gnupg 1.4.10-2ubuntu1.2 gnupg2 2.0.14-1ubuntu1.5 Ubuntu 8.04 LTS: gnupg 1.4.6-2ubuntu5.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1682-1 CVE-2012-6085 Package Information: https://launchpad.net/ubuntu/+source/gnupg/1.4.11-3ubuntu4.1 https://launchpad.net/ubuntu/+source/gnupg2/2.0.17-2ubuntu3.1 https://launchpad.net/ubuntu/+source/gnupg/1.4.11-3ubuntu2.2 https://launchpad.net/ubuntu/+source/gnupg2/2.0.17-2ubuntu2.12.04.2 https://launchpad.net/ubuntu/+source/gnupg/1.4.11-3ubuntu1.11.10.2 https://launchpad.net/ubuntu/+source/gnupg2/2.0.17-2ubuntu2.11.10.2 https://launchpad.net/ubuntu/+source/gnupg/1.4.10-2ubuntu1.2 https://launchpad.net/ubuntu/+source/gnupg2/2.0.14-1ubuntu1.5 https://launchpad.net/ubuntu/+source/gnupg/1.4.6-2ubuntu5.2 . A specific crafted key import could lead to GnuPG corrupting the keyring. Ubuntu users are recommended to apply updates.. GnuPG, Keyring Issue, Ubuntu Update, Security Notice. . Severity: Critical. LinuxSecurity.com Team
APT now more thoroughly verifies imported keyrings.. =========================================================================Ubuntu Security Notice USN-1475-1 June 15, 2012 apt update ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.04 LTS - Ubuntu 8.04 LTS Summary: APT now more thoroughly verifies imported keyrings. Software Description: - apt: Advanced front-end for dpkg Details: Georgi Guninski discovered that APT relied on GnuPG argument order and did not check GPG subkeys when validating imported keyrings via apt-key net-update. While it appears that a man-in-the-middle attacker cannot exploit this, as a hardening measure this update adjusts apt-key to validate all subkeys when checking for key collisions. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: apt 0.8.16~exp12ubuntu10.1 Ubuntu 11.10: apt 0.8.16~exp5ubuntu13.4 Ubuntu 11.04: apt 0.8.13.2ubuntu4.5 Ubuntu 10.04 LTS: apt 0.7.25.3ubuntu9.12 Ubuntu 8.04 LTS: apt 0.7.9ubuntu17.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1475-1 https://bugs.launchpad.net/ubuntu/+source/apt/+bug/1013128 Package Information: https://launchpad.net/ubuntu/+source/apt/0.8.16~exp12ubuntu10.1 https://launchpad.net/ubuntu/+source/apt/0.8.16~exp5ubuntu13.4 https://launchpad.net/ubuntu/+source/apt/0.8.13.2ubuntu4.5 https://launchpad.net/ubuntu/+source/apt/0.7.25.3ubuntu9.12 https://launchpad.net/ubuntu/+source/apt/0.7.9ubuntu17.5 . APT package update in Ubuntu 12.04 LTS enhances keyring validation security against attacks..Ubuntu, APT, Keyring Verification. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.