VulnerabilityModified
CVE-2014-0488
APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to have unspecified impact via crafted repository data.
MEDIUM 6.8EPSS 2.08%
Does this matter?
Lower severity and a low EPSS score (2.08%). Track it; it rarely justifies an emergency change on its own.
Description
APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to have unspecified impact via crafted repository data.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.08% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- debian/advanced package tool
- Source
- security@debian.org
References
- http://secunia.com/advisories/61275
- http://secunia.com/advisories/61286
- http://ubuntu.com/usn/usn-2348-1Patch, Vendor Advisory
- http://www.debian.org/security/2014/dsa-3025Vendor Advisory
- http://secunia.com/advisories/61275
- http://secunia.com/advisories/61286
- http://ubuntu.com/usn/usn-2348-1Patch, Vendor Advisory
- http://www.debian.org/security/2014/dsa-3025Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.