# the archive-keyring keys needs to be signed with the master key
# (otherwise it does not make sense from a security POV)
net_update() {
+ # Disabled for now as code is insecure
+ exit 1
+
if [ -z "$ARCHIVE_KEYRING_URI" ]; then
echo >&2 "ERROR: Your distribution is not supported in net-update as no uri for the archive-keyring is set"
exit 1
+apt (0.8.16~exp5ubuntu11) UNRELEASED; urgency=low
+
+ [ Colin Watson ]
+ * ftparchive/cachedb.cc:
+ - fix buffersize in bytes2hex
+
+ [ Marc Deslauriers ]
+ * SECURITY UPDATE: Disable apt-key net-update for now, as validation
+ code is insecure.
+ - cmdline/apt-key: exit immediately out of net_update().
+ - CVE number pending
+
+ -- Michael Vogt <michael.vogt@ubuntu.com> Thu, 22 Sep 2011 17:28:49 +0200
+
apt (0.8.16~exp5ubuntu10) oneiric; urgency=low
* methods/https.cc:
libapt does not segfault if the cache is remapped in between
(LP: #812862)
- [ Colin Watson ]
- * ftparchive/cachedb.cc:
- - fix buffersize in bytes2hex
-
-- Michael Vogt <michael.vogt@ubuntu.com> Fri, 29 Jul 2011 13:44:01 +0200
apt (0.8.16~exp4) experimental; urgency=low