PT-2014-1779 · Debian+1 · Apt+1

Jakub Wilk

·

Published

2014-06-12

·

Updated

2020-01-08

·

CVE-2014-0478

CVSS v2.0

4.0

Medium

VectorAV:N/AC:H/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions apt versions prior to 1.0.4
Description The issue concerns multiple vulnerabilities in the apt package of the Debian GNU/Linux operating system, which can be exploited to compromise the integrity and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, the problem arises from the failure to properly validate source packages, allowing man-in-the-middle attackers to download and install malicious packages by removing the Release signature.
Recommendations For versions prior to 1.0.4, update to version 1.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the package installation process to minimize the risk of exploitation. Avoid using untrusted sources for package downloads until the issue is resolved.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03029
CVE-2014-0478
DLA-0005-1
DSA-2958-1
USN-2246-1

Affected Products

Ubuntu
Apt