CVE-2014-0487: High severity kali linux package management (apt) vulnerability
Published Nov 3, 2014
·Updated
APT before 1.0.9 does not verify downloaded files if they have been modified as indicated using the If-Modified-Since header, which has unspecified impact and attack vectors.
Affected Software
2 affected components
Debian Advanced Package Tool=1.0.3
Debian Advanced Package Tool=1.0.7
Remediation
Patch Available
Event History
Nov 3, 2014
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-0487?
The severity of CVE-2014-0487 is considered moderate, primarily due to the lack of verification for downloaded files.
2
How do I fix CVE-2014-0487?
To fix CVE-2014-0487, upgrade to APT version 1.0.9 or later.
3
What are the affected versions of APT in CVE-2014-0487?
The affected versions of APT are 1.0.3 and 1.0.7.
4
What impact does CVE-2014-0487 have on users?
CVE-2014-0487 may allow an attacker to modify downloaded files without detection.
5
Which operating systems are impacted by CVE-2014-0487?
CVE-2014-0487 impacts Debian systems that utilize the affected versions of APT.