GPGv Security Flaw in APT Package Manager by Debian
CVE-2009-1358

Currently unrated

Key Information:

Vendor

Debian

Vendor
CVE Published:
21 April 2009

What is CVE-2009-1358?

APT prior to version 0.7.21 fails to accurately check error codes from gpgv, leading to a scenario where the package manager wrongly considers a repository valid. This could enable remote adversaries to deceive APT into installing repositories that maliciously alter system files or compromise security integrity, particularly when the associated signing key has been revoked or is outdated.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.