7.5
CVSSv2

CVE-2014-0489

Published: 03/11/2014 Updated: 08/01/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

APT prior to 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote malicious users to execute arbitrary code via a crafted package.

Vulnerable Product Search on Vulmon Subscribe to Product

debian advanced package tool 1.0.5

debian advanced package tool 1.0.3

debian advanced package tool 1.0.7

Vendor Advisories

Several security issues were fixed in APT ...
It was discovered that APT, the high level package manager, does not properly invalidate unauthenticated data (CVE-2014-0488), performs incorrect verification of 304 replies (CVE-2014-0487), does not perform the checksum check when the Acquire::GzipIndexes option is used (CVE-2014-0489) and does not properly perform validation for binary packages d ...