---------------------------------------------------------------------- Secunia is pleased to announce the release of the annual Secunia report for 2008. Highlights from the 2008 report: * Vulnerability Research * Software Inspection Results * Secunia Research Highlights * Secunia Advisory Statistics Request the full 2008 Report here: http://secunia.com/advisories/try_vi/request_2008_report/ Stay Secure, Secunia ---------------------------------------------------------------------- TITLE: apt Package Signature Verification Security Bypass SECUNIA ADVISORY ID: SA34829 VERIFY ADVISORY: http://secunia.com/advisories/34829/ DESCRIPTION: A security issue has been reported in apt, which can be exploited by malicious people to bypass certain security restrictions. The security issue is caused due to apt checking for the "GOODSIG" instead of the "VALIDSIG" return value when launching "gpgv" to verify packages, which results in apt accepting packages signed with expired or revoked keys. Note: Additionally, an error exists within the daily apt cron script when handling certain dates. This can lead to automatic updates being stopped or disabled. SOLUTION: Update to version 0.7.21. PROVIDED AND/OR DISCOVERED BY: Reported in a Debian bug by martin f krafft. ORIGINAL ADVISORY: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=433091 http://packages.debian.org/changelogs/pool/main/a/apt/apt_0.7.21/changelog#versionversion0.7.21 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------