CVE-2011-3374

SOURCE - nist

Summary

It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.

EPSS Score: 0.00164 (0.529)

Common Weakness Enumeration (CWE)

SOURCE - nist

Improper Verification of Cryptographic Signature


debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/aptdebdebian12>=2.6.1Not yet available
debian/aptdebdebian10>=1.8.2.3Not yet available
debian/aptdebdebian11>=2.2.4Not yet available
debian/aptdebdebian13>=2.9.3Not yet available
debian/aptdebdebianunstable>=2.9.3Not yet available

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

2.2


EXPLOITS FOUND

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

3.7low

ubuntu

CREATED


UPDATED



EXPLOITABILITY SCORE

2.2


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

3.7critical

inthewild

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND

-


COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE