Filtered by vendor Debian Subscriptions
Filtered by product Unattended-upgrades Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2015-1330 2 Canonical, Debian 2 Ubuntu Linux, Unattended-upgrades 2017-09-22 N/A
unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which allows remote man-in-the-middle attackers to upload and execute arbitrary packages via unspecified vectors.