4
CVSSv2

CVE-2014-0478

Published: 17/06/2014 Updated: 08/01/2020
CVSS v2 Base Score: 4 | Impact Score: 4.9 | Exploitability Score: 4.9
VMScore: 356
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:P

Vulnerability Summary

APT prior to 1.0.4 does not properly validate source packages, which allows man-in-the-middle malicious users to download and install Trojan horse packages by removing the Release signature.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian advanced package tool

Vendor Advisories

Debian Bug report logs - #749795 apt: CVE-2014-0478: no authentication checks for source packages Package: apt; Maintainer for apt is APT Development Team <deity@listsdebianorg>; Source for apt is src:apt (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date: Thu, 29 May 2014 21:09:02 UTC Severity: ...
An attacker could trick APT into installing altered source packages ...