Files
poky/meta/recipes-devtools
Chong Lu 6a30031708 apt: fix for CVE-2014-0478
APT before 1.0.4 does not properly validate source packages, which allows
man-in-the-middle attackers to download and install Trojan horse packages
by removing the Release signature.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0478

(From OE-Core rev: 3dd692fcf2b0c11731b3f30abdf2b1878458a898)

Signed-off-by: Wenlin Kang <wenlin.kang@windriver.com>
Signed-off-by: Chong Lu <Chong.Lu@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2014-09-30 14:10:34 +01:00
..
2014-09-30 14:10:34 +01:00
2014-03-02 17:25:28 +00:00
2014-07-19 00:09:01 +01:00
2014-09-10 15:38:55 +01:00
2014-07-16 10:20:50 +01:00
2014-09-22 13:04:21 +01:00
2014-01-02 12:50:24 +00:00
2014-08-28 15:12:44 +01:00
2014-07-17 12:28:50 +01:00
2014-08-02 09:26:17 +01:00
2014-09-22 13:04:22 +01:00
2014-08-28 15:12:42 +01:00
2014-07-19 00:18:21 +01:00
2014-09-22 13:04:22 +01:00
2014-08-28 15:12:44 +01:00
2014-08-11 10:53:05 +01:00
2014-09-03 16:00:28 +01:00
2014-09-16 22:14:09 +01:00
2014-08-28 15:12:44 +01:00
2014-04-10 17:35:15 +01:00
2014-08-23 09:26:10 +01:00
2013-08-13 23:05:58 +01:00