Y
Hacker News
new
|
ask
|
show
|
jobs
HTTP redirect vulnerability in apt package manager
(
lists.debian.org
)
10 points
by
dansimau
2708 days ago
3 comments
mondoshawan
2708 days ago
Ironic, given the previous discussion on why apt shouldn't use HTTPS connections. With full end-to-end SSL validation, this kind of vulnerability can't exist. Should be interesting to see how the community reacta to this.
link
est31
2708 days ago
Weren't PGP signatures supposed to ensure integrity? How is this being bypassed?
link
detaro
2708 days ago
The attack can inject fake hashes into the process, so it can pretend the file has the correct checksum:
https://justi.cz/security/2019/01/22/apt-rce.html
link
jwilk
2708 days ago
Discussed on HN:
https://news.ycombinator.com/item?id=18968370
link
jwilk
2708 days ago
Please use the original title.
link