Authentication Flaw in APT Affects Multiple Versions
CVE-2014-0488

Currently unrated

Key Information:

Vendor
Debian
Vendor
CVE Published:
3 November 2014

Summary

An issue in APT versions prior to 1.0.9 allows for an opportunity where repository data is not properly invalidated when transitioning from an unauthenticated to an authenticated state. This flaw can potentially be exploited by remote attackers, leading to unauthorized access and manipulation of repository data. Users of affected versions are advised to upgrade to ensure secure transitions during package updates.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.