CVE-2015-1330
unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which allows remote man-in-the-middle attackers to upload and…
Does this matter?
Lower severity and a low EPSS score (1.44%). Track it; it rarely justifies an emergency change on its own.
Description
unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which allows remote man-in-the-middle attackers to upload and execute arbitrary packages via unspecified vectors.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.44% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- canonical/ubuntu linux · debian/unattended-upgrades
- Source
- security@ubuntu.com
References
- http://metadata.ftp-master.debian.org/changelogs//main/u/unattended-upgrades/unattended-upgrades_0.86.1_changelog
- http://www.debian.org/security/2015/dsa-3297
- http://www.securitytracker.com/id/1032738
- http://www.ubuntu.com/usn/USN-2657-1
- http://metadata.ftp-master.debian.org/changelogs//main/u/unattended-upgrades/unattended-upgrades_0.86.1_changelog
- http://www.debian.org/security/2015/dsa-3297
- http://www.securitytracker.com/id/1032738
- http://www.ubuntu.com/usn/USN-2657-1
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.