Article 47KRZ Justicz: Remote Code Execution in apt/apt-get

Justicz: Remote Code Execution in apt/apt-get

by
corbet
from LWN.net on (#47KRZ)
Max Justicz describes avulnerability in apt-get and how to prevent it. "I found avulnerability in apt that allows a network man-in-the-middle (or amalicious package mirror) to execute arbitrary code as root on a machineinstalling any package. The bug has been fixed in the latest versions ofapt. If you're worried about being exploited during the update process, youcan protect yourself by disabling HTTP redirects while you update."
External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments