CVE-2014-0488

critical

Description

APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to have unspecified impact via crafted repository data.

References

http://www.debian.org/security/2014/dsa-3025

http://ubuntu.com/usn/usn-2348-1

http://secunia.com/advisories/61286

http://secunia.com/advisories/61275

Details

Source: Mitre, NVD

Published: 2014-11-03

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical