Arbitrary Code Execution Vulnerability in APT by Debian
CVE-2014-0489

Currently unrated

Key Information:

Vendor
Debian
Vendor
CVE Published:
3 November 2014

Summary

The vulnerability in APT allows remote attackers to execute arbitrary code by crafting malicious packages. When the Acquire::GzipIndexes option is enabled, APT fails to validate checksums, making it susceptible to exploit. This can lead to unauthorized actions executed on the system, posing significant security risks to users of affected versions prior to 1.0.9.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.