<= Back

AOSA-2016-0035: Update APT

Please update your apt package to version 1.3.1-2.

A security vulnerability in APT has recently been disclosed that the "high level package manager, does not properly handle errors when validating signatures on InRelease files. An attacker able to man-in-the-middle HTTP requests to an apt repository that uses InRelease files (clearsigned Release files), can take advantage of this flaw to circumvent the signature of the InRelease file, leading to arbitrary code execution."

A CVE is assigned for this issue:

CVE-2016-1252.

Relevant documentation: