Skip to content

HTTP redirect vulnerability in apt package manager

lists.debian.org
10 pointsdansimau5 comments
On HN

Comments

Ironic, given the previous discussion on why apt shouldn't use HTTPS connections. With full end-to-end SSL validation, this kind of vulnerability can't exist. Should be interesting to see how the community reacta to this.

Weren't PGP signatures supposed to ensure integrity? How is this being bypassed?

The attack can inject fake hashes into the process, so it can pretend the file has the correct checksum: https://justi.cz/security/2019/01/22/apt-rce.html

Please use the original title.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.