CVE-2014-0478

EUVD-2014-0513
APT before 1.0.4 does not properly validate source packages, which allows man-in-the-middle attackers to download and install Trojan horse packages by removing the Release signature.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:N/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
Affected Products (NVD)
VendorProductVersion
debianadvanced_package_tool
𝑥
≤ 1.0.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
apt
bookworm
2.6.1
fixed
bullseye
2.2.4
fixed
sid
2.9.10
fixed
trixie
2.9.10
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apt
lucid
Fixed 0.7.25.3ubuntu9.15
released
precise
Fixed 0.8.16~exp12ubuntu10.17
released
saucy
Fixed 0.9.9.1~ubuntu3.2
released
trusty
Fixed 1.0.1ubuntu2.1
released