Lucene search

K
nvd[email protected]NVD:CVE-2014-0488
HistoryNov 03, 2014 - 10:55 p.m.

CVE-2014-0488

2014-11-0322:55:07
CWE-20
web.nvd.nist.gov
4

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0.005

Percentile

77.1%

APT before 1.0.9 does not “invalidate repository data” when moving from an unauthenticated to authenticated state, which allows remote attackers to have unspecified impact via crafted repository data.

Affected configurations

Nvd
Node
debianadvanced_package_toolMatch1.0.3
OR
debianadvanced_package_toolMatch1.0.7
VendorProductVersionCPE
debianadvanced_package_tool1.0.3cpe:2.3:a:debian:advanced_package_tool:1.0.3:*:*:*:*:*:*:*
debianadvanced_package_tool1.0.7cpe:2.3:a:debian:advanced_package_tool:1.0.7:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0.005

Percentile

77.1%