3 ms·
Does it include the fix for apt's recent mirror redirect vulnerability? If not, any update to a fresh system would be trivially susceptible to a MITM attack if
by jake_the_third 8y ago
Does it include the fix for apt's recent mirror redirect vulnerability? If not, any update to a fresh system would be trivially susceptible to a MITM attack if redirects aren't disabled. This includes docker images as well: https://justi.cz/security/2019/01/22/apt-rce.html https://justi.cz/security/2019/01/22/apt-rce.html
Canonical really should enable https as an additional layer of protection. This isn't the first time a bug in apt's authentication was found and it's unlikely that this bug will be the last.
- powersj 8y agoFixed in January: https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-3462.html https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2... edit: the updated, point release ISOs will have the fix