Loading...
Loading...
apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.
April 21, 2009
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2009-1358
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.