Arbitrary Code Execution Vulnerability in APT by Debian
CVE-2014-0489
Currently unrated
Summary
The vulnerability in APT allows remote attackers to execute arbitrary code by crafting malicious packages. When the Acquire::GzipIndexes option is enabled, APT fails to validate checksums, making it susceptible to exploit. This can lead to unauthorized actions executed on the system, posing significant security risks to users of affected versions prior to 1.0.9.
References
Timeline
Vulnerability published
Vulnerability Reserved