Ubuntu Security Notice (C) 2012-2013 Canonical, Inc. / NASL script (C) 2012-2013 Tenable Network Security, Inc.
The remote Ubuntu host is missing a security-related patch.
Georgi Guninski discovered that APT did not properly validate imported
keyrings via apt-key net-update. USN-1475-1 added additional
verification for imported keyrings, but it was insufficient. If a
remote attacker were able to perform a man-in-the-middle attack, this
flaw could potentially be used to install altered packages. This
update corrects the issue by disabling the net-update option
completely. A future update will re-enable the option with corrected
Update the affected apt package.
Risk factor :
Low / CVSS Base Score : 2.6
Family: Ubuntu Local Security Checks
Nessus Plugin ID: 59554 ()
CVE ID: CVE-2012-0954