Age | Commit message (Collapse) | Author | |
---|---|---|---|
2011-06-06 | * apt-pkg/indexcopy.cc: | David Kalnischkies | |
- Verify that the first line of an InRelease file is a PGP header for a signed message. Otherwise a man-in-the-middle can prefix a valid InRelease file with his own data! (CVE-2011-1829) |