HTTP redirect vulnerability in apt package manager

by dansimauon 1/22/2019, 1:54 PMwith 5 comments

by mondoshawanon 1/22/2019, 4:45 PM

Ironic, given the previous discussion on why apt shouldn't use HTTPS connections. With full end-to-end SSL validation, this kind of vulnerability can't exist. Should be interesting to see how the community reacta to this.

by est31on 1/22/2019, 2:08 PM

Weren't PGP signatures supposed to ensure integrity? How is this being bypassed?

by jwilkon 1/22/2019, 3:38 PM

Please use the original title.