Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is not simulated, which allows remote attackers to install arbitrary packages via a man-in-the-middle attack.
| Software | From | Fixed in |
|---|---|---|
| sebastian_heinlein / aptdaemon | - | 0.42.x |
| canonical / ubuntu_linux | 12.04-lts | 12.04-lts.x |
| sebastian_heinlein / aptdaemon | 0.32 | 0.32.x |
| canonical / ubuntu_linux | 11.04 | 11.04.x |
| sebastian_heinlein / aptdaemon | 0.20 | 0.20.x |
| sebastian_heinlein / aptdaemon | 0.41 | 0.41.x |
| sebastian_heinlein / aptdaemon | 0.30 | 0.30.x |
| canonical / ubuntu_linux | 11.10 | 11.10.x |
| sebastian_heinlein / aptdaemon | 0.33 | 0.33.x |
| sebastian_heinlein / aptdaemon | 0.40 | 0.40.x |
| sebastian_heinlein / aptdaemon | 0.34 | 0.34.x |
| sebastian_heinlein / aptdaemon | 0.31 | 0.31.x |