CVE-2015-1330
Publication date 29 June 2015
Last updated 24 July 2024
Ubuntu priority
unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which allows remote man-in-the-middle attackers to upload and execute arbitrary packages via unspecified vectors.
Status
Package | Ubuntu Release | Status |
---|---|---|
unattended-upgrades | ||
14.04 LTS trusty |
Fixed 0.82.1ubuntu2.3
|
|
References
Related Ubuntu Security Notices (USN)
- USN-2657-1
- unattended-upgrades vulnerability
- 29 June 2015