A Look In the Mirror: Attacks on Package Managers

A Look In the Mirror: Attacks on Package Managers. Justin Cappos, Justin Samuel, Scott Baker, and John Hartman. CSS 2008.

Read the paper [pdf]

Related website

http://www.cs.arizona.edu/people/justin/packagemanagersecurity/

Press

http://it.slashdot.org/article.pl?sid=08/07/10/227220

http://www.heise-online.co.uk/security/Linux-package-management-systems-not-completely-secure–/news/111103

http://www.heise.de/newsticker/Bericht-Paket-Management-Systeme-unter-Linux-nur-bedingt-vertrauenswuerdig–/meldung/110908

http://lwn.net/Articles/290209/

http://lwn.net/Articles/289883/

Bug Reports / Updates

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=499897

https://bugs.launchpad.net/ubuntu/+source/apt/+bug/247445

http://lizards.opensuse.org/2008/07/16/package-management-security-on-opensuse/

http://lists.baseurl.org/pipermail/yum-devel/2008-August/005350.html

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=491374

http://rhn.redhat.com/errata/RHSA-2008-0815.html

http://www.mail-archive.com/fedora-infrastructure-list@redhat.com/msg03556.html

Leave a Reply