HTTP redirect vulnerability in apt package managerlists.debian.org 10 pointsdansimau7 years ago5 commentsSaveHideCopy link On HNComments−mondoshawan7yIronic, given the previous discussion on why apt shouldn't use HTTPS connections. With full end-to-end SSL validation, this kind of vulnerability can't exist. Should be interesting to see how the community reacta to this.−est317yWeren't PGP signatures supposed to ensure integrity? How is this being bypassed?−detaro7yThe attack can inject fake hashes into the process, so it can pretend the file has the correct checksum: https://justi.cz/security/2019/01/22/apt-rce.html−jwilk7yDiscussed on HN:https://news.ycombinator.com/item?id=18968370−jwilk7yPlease use the original title.
Comments
Ironic, given the previous discussion on why apt shouldn't use HTTPS connections. With full end-to-end SSL validation, this kind of vulnerability can't exist. Should be interesting to see how the community reacta to this.
Weren't PGP signatures supposed to ensure integrity? How is this being bypassed?
The attack can inject fake hashes into the process, so it can pretend the file has the correct checksum: https://justi.cz/security/2019/01/22/apt-rce.html
Discussed on HN:
https://news.ycombinator.com/item?id=18968370
Please use the original title.