CVE-2015-1330

Publication date 29 June 2015

Last updated 24 July 2024


Ubuntu priority

unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which allows remote man-in-the-middle attackers to upload and execute arbitrary packages via unspecified vectors.

Status

Package Ubuntu Release Status
unattended-upgrades 15.04 vivid
Fixed 0.83.6ubuntu1
14.10 utopic
Fixed 0.82.8ubuntu0.3
14.04 LTS trusty
Fixed 0.82.1ubuntu2.3
12.04 LTS precise
Fixed 0.76ubuntu1.1

References

Related Ubuntu Security Notices (USN)

    • USN-2657-1
    • unattended-upgrades vulnerability
    • 29 June 2015

Other references