CVE-2014-7206
15.10.2014, 14:55
The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.
| Vendor | Product | Version |
|---|---|---|
| debian | advanced_package_tool | 𝑥 ≤ 1.0.9.1 |
| debian | advanced_package_tool | 1.0.8 |
| debian | apt | 0.9.7.9:ubunto3 |
| debian | apt | 0.9.7.9:ubunto4 |
| debian | apt | 0.9.7.9:ubunto5 |
| debian | apt | 1.0.9 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References