CVE-2014-0478
17.06.2014, 14:55
APT before 1.0.4 does not properly validate source packages, which allows man-in-the-middle attackers to download and install Trojan horse packages by removing the Release signature.Enginsight
Vendor | Product | Version |
---|---|---|
debian | advanced_package_tool | 𝑥 ≤ 1.0.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References