]> git.saurik.com Git - apt.git/commit
* apt-pkg/indexcopy.cc:
authorDavid Kalnischkies <kalnischkies@gmail.com>
Mon, 6 Jun 2011 19:29:16 +0000 (21:29 +0200)
committerDavid Kalnischkies <kalnischkies@gmail.com>
Mon, 6 Jun 2011 19:29:16 +0000 (21:29 +0200)
commit2e3c9d6452e69dcb5c83732fbda27b747bc997f4
treebc5e845c507f605f956964e45519ed4e73d7d341
parent89a1aa5dd55a3469c92720c7fcb90779f90b61f0
* apt-pkg/indexcopy.cc:
  - Verify that the first line of an InRelease file is a PGP header
    for a signed message. Otherwise a man-in-the-middle can prefix
    a valid InRelease file with his own data! (CVE-2011-1829)
apt-pkg/indexcopy.cc
debian/changelog
methods/gpgv.cc
test/integration/test-ubuntu-bug-784473-InRelease-one-message-only [new file with mode: 0755]