| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.63897 |
| Category: | Ubuntu Local Security Checks |
| Title: | Ubuntu USN-762-1 (apt) |
| Summary: | Ubuntu USN-762-1 (apt) |
| Description: | The remote host is missing an update to apt announced via advisory USN-762-1. Details follow: Alexandre Martani discovered that the APT daily cron script did not check the return code of the date command. If a machine is configured for automatic updates and is in a time zone where DST occurs at midnight, under certain circumstances automatic updates might not be applied and could become permanently disabled. (CVE-2009-1300) Michael Casadevall discovered that APT did not properly verify repositories signed with a revoked or expired key. If a repository were signed with only an expired or revoked key and the signature was otherwise valid, APT would consider the repository valid. (https://launchpad.net/bugs/356012) Solution: The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: apt 0.6.43.3ubuntu3.1 Ubuntu 8.04 LTS: apt 0.7.9ubuntu17.2 Ubuntu 8.10: apt 0.7.14ubuntu6.1 In general, a standard system upgrade is sufficient to effect the necessary changes. http://www.securityspace.com/smysecure/catid.html?in=USN-762-1 |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-1300 http://www.openwall.com/lists/oss-security/2009/04/08/11 Debian Security Information: DSA-1779 (Google Search) http://www.debian.org/security/2009/dsa-1779 http://www.ubuntulinux.org/support/documentation/usn/usn-762-1 http://secunia.com/advisories/34829 http://secunia.com/advisories/34832 http://secunia.com/advisories/34874 |
| Copyright | Copyright (c) 2009 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|