CVE-2009-1300: Input Validation
Published Apr 16, 2009
·Updated
apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight.
Affected Software
1 affected component
Debian Advanced Package Tool=0.7.20
Event History
Apr 16, 2009
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1300?
CVE-2009-1300 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2009-1300?
To resolve CVE-2009-1300, you should upgrade the Advanced Package Tool (APT) to a version later than 0.7.20.
3
What impact does CVE-2009-1300 have on system security?
CVE-2009-1300 can prevent timely loading of security updates, thus posing a risk to systems in affected time zones.
4
Which versions of APT are affected by CVE-2009-1300?
CVE-2009-1300 affects APT version 0.7.20 and possibly earlier versions.
5
Is CVE-2009-1300 specific to Debian systems?
Yes, CVE-2009-1300 specifically impacts the Debian Advanced Package Tool.