Lucene search

K
osvGoogleOSV:DLA-53-1
HistorySep 03, 2014 - 12:00 a.m.

apt - security update

2014-09-0300:00:00
Google
osv.dev
12

EPSS

0.027

Percentile

90.4%

It was discovered that APT, the high level package manager, does not
properly invalidate unauthenticated data (CVE-2014-0488),
performs incorrect verification of 304 replies (CVE-2014-0487)
and does not perform the checksum check when the Acquire::GzipIndexes option is used
(CVE-2014-0489).

For Debian 6 Squeeze, these issues have been fixed in apt version 0.8.10.3+squeeze3