Vulnerabilities (CVE)

Filtered by vendor Debian Subscribe
Filtered by product Unattended-upgrades
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-1330 2 Canonical, Debian 2 Ubuntu Linux, Unattended-upgrades 2024-11-21 6.8 MEDIUM N/A
unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which allows remote man-in-the-middle attackers to upload and execute arbitrary packages via unspecified vectors.