Lucene search

K
cveMitreCVE-2009-1300
HistoryApr 16, 2009 - 3:12 p.m.

CVE-2009-1300

2009-04-1615:12:57
CWE-20
mitre
web.nvd.nist.gov
46
cve-2009-1300
apt 0.7.20
date command
dst
security updates

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.5

Confidence

Low

EPSS

0.007

Percentile

81.0%

apt 0.7.20 does not check when the date command returns an “invalid date” error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight.

Affected configurations

Nvd
Node
debianadvanced_package_toolMatch0.7.20
VendorProductVersionCPE
debianadvanced_package_tool0.7.20cpe:2.3:a:debian:advanced_package_tool:0.7.20:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.5

Confidence

Low

EPSS

0.007

Percentile

81.0%