Debian Security Advisory - DSA-3025-1 apt - security update

by
Anonymous Coward
in linux on (#2SK4)
Debian has announced a security advisory about its apt-get software, and recommends that you upgrade your apt packages ... with apt, of course.
"It was discovered that APT, the high level package manager, does not properly invalidate unauthenticated data (CVE-2014-0488), performs incorrect verification of 304 replies (CVE-2014-0487), does not perform the checksum check when the Acquire::GzipIndexes option is used (CVE-2014-0489) and does not properly perform validation for binary packages downloaded by the apt-get download command (CVE-2014-0490)."
This update comes to you courtesy of the IOERROR Twitter account.

Re: Some glaring security holes? (Score: 1)

by zafiro17@pipedot.org on 2014-09-21 19:19 (#2SQ6)

That stops them from getting in, but doesn't stop them from flooding your system (and your logs) with hundreds of tries per second, right?

I'm glad there are no intruders in my apartment, but I'm also tired of them banging on the door. I need a system that paints a big "F U" on the front door and electrifies the doorknob, front walk, and maybe parts of the sidewalk :)

No really, for my front door. Although its parallel in code for my VPS would be nice, too :)
Post Comment
Subject
Comment
Captcha
What is 6 add two?