Live data from Hacker News

HTTP redirect vulnerability in apt package manager

lists.debian.org

1–6 of 6 posts

Re: HTTP redirect vulnerability in apt package manager

#6
post #3
post #2

Weren't PGP signatures supposed to ensure integrity? How is this being bypassed?

The attack can inject fake hashes into the process, so it can pretend the file has the correct checksum: https://justi.cz/security/2019/01/22/apt-rce.html

Discussed on HN:

https://news.ycombinator.com/item?id=18968370