yocto ▾
›
master ▾
›
vulnerability
›
CVE-2011-3374
Component Overview
Vulnerability Overview
Name
CVE-2011-3374
Source
NVD (
link
)
Debian (
link
)
Description
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.
CWEs
CWE-347
Published Date
Nov 26, 2019
Updated Date
Jun 16, 2026
Workaround
-
Advisories
https://access.redhat.com/security/cve/cve-2011-3374
Broken Link
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=642480
Issue Tracking
https://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-3374.html
Third Party Advisory
https://seclists.org/fulldisclosure/2011/Sep/221
Exploit
https://security-tracker.debian.org/tracker/CVE-2011-3374
Third Party Advisory
https://snyk.io/vuln/SNYK-LINUX-APT-116518
Broken Link
https://ubuntu.com/security/CVE-2011-3374
Third Party Advisory
https://access.redhat.com/security/cve/cve-2011-3374
Broken Link
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=642480
Issue Tracking
https://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-3374.html
Third Party Advisory
https://seclists.org/fulldisclosure/2011/Sep/221
Exploit
https://security-tracker.debian.org/tracker/CVE-2011-3374
Third Party Advisory
https://snyk.io/vuln/SNYK-LINUX-APT-116518
Broken Link
https://ubuntu.com/security/CVE-2011-3374
Third Party Advisory
Analysis
#
Affected Component
Analysis
apt
Exploitable
Vulnerability Ratings
#
3.7
CVSSv31
4.3
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
apt
yocto
kirkstone
2.4.5
Exploitable
apt
yocto
scarthgap
2.6.1
Exploitable