CVE-2014-0478: Input Validation
Published May 29, 2014
·Updated
APT before 1.0.4 does not properly validate source packages, which allows man-in-the-middle attackers to download and install Trojan horse packages by removing the Release signature.
Affected Software
3 affected componentsFixes available
debian/apt<=0.9.7.9+deb7u1, <=1.0.3
1.0.40.8.10.3+squeeze20.9.7.9+deb7u2
debian/apt
2.2.42.6.12.9.7
Debian Advanced Package Tool<=1.0.3
Event History
Jun 17, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-0478?
CVE-2014-0478 is considered to have a high severity as it allows man-in-the-middle attackers to install malicious packages.
2
How do I fix CVE-2014-0478?
To fix CVE-2014-0478, you should upgrade to APT version 1.0.4 or later.
3
Which versions of APT are affected by CVE-2014-0478?
APT versions prior to 1.0.4, including 0.9.7.9+deb7u1 and earlier, are affected by CVE-2014-0478.
4
What type of attack does CVE-2014-0478 enable?
CVE-2014-0478 enables man-in-the-middle attacks that can result in the installation of Trojan horse packages.
5
Is upgrading APT the only mitigation for CVE-2014-0478?
Upgrading APT to version 1.0.4 or later is the primary mitigation for CVE-2014-0478 to ensure proper validation of source packages.