CVE-2009-1358
EPSS 1.4%
Description
apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.
How to fix CVE-2009-1358
To remediate CVE-2009-1358, upgrade the affected package to a fixed version below.
- Debian/apt—upgrade to 0.7.21 or later
Is CVE-2009-1358 being exploited?
Low — EPSS is 1.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.7.21