PT-2014-1779 · Debian+1 · Apt+1
Jakub Wilk
·
Published
2014-06-12
·
Updated
2020-01-08
·
CVE-2014-0478
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:H/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
apt versions prior to 1.0.4
Description
The issue concerns multiple vulnerabilities in the apt package of the Debian GNU/Linux operating system, which can be exploited to compromise the integrity and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, the problem arises from the failure to properly validate source packages, allowing man-in-the-middle attackers to download and install malicious packages by removing the Release signature.
Recommendations
For versions prior to 1.0.4, update to version 1.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the package installation process to minimize the risk of exploitation. Avoid using untrusted sources for package downloads until the issue is resolved.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ubuntu
Apt