CVEs Blog | G5 Cyber Security

CVE-2015-1330 – unattended-upgrades before 0.86.1 does not properly authenticate packages

unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which allows remote man-in-the-middle attackers to upload and execute arbitrary packages via unspecified vectors.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1330

Reference (s):

Exit mobile version