Vulnerability Name: | CVE-2015-1330 (CCN-104419) | ||||||||||||||||
Assigned: | 2015-06-29 | ||||||||||||||||
Published: | 2015-06-29 | ||||||||||||||||
Updated: | 2017-09-22 | ||||||||||||||||
Summary: | unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which allows remote man-in-the-middle attackers to upload and execute arbitrary packages via unspecified vectors. | ||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-287 | ||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-1330 Source: CONFIRM Type: UNKNOWN http://metadata.ftp-master.debian.org/changelogs//main/u/unattended-upgrades/unattended-upgrades_0.86.1_changelog Source: CCN Type: BugTraq Mailing List, Mon, 29 Jun 2015 19:13:52 +0200 [SECURITY] [DSA 3297-1] unattended-upgrades security update Source: DEBIAN Type: UNKNOWN DSA-3297 Source: SECTRACK Type: UNKNOWN 1032738 Source: UBUNTU Type: UNKNOWN USN-2657-1 Source: XF Type: UNKNOWN debian-unattendedupgrades-sec-bypass(104419) Source: CCN Type: Debian Web site unattended-upgrades Source: CCN Type: Debian Security Advisory DSA-3297-1 unattended-upgrades -- security update | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |