CVE-2014-0488: Input Validation
Published Nov 3, 2014
·Updated
APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to have unspecified impact via crafted repository data.
Affected Software
2 affected components
Debian Advanced Package Tool=1.0.3
Debian Advanced Package Tool=1.0.7
Remediation
Patch Available
Event History
Nov 3, 2014
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-0488?
CVE-2014-0488 is considered a medium severity vulnerability due to the potential for attackers to exploit crafted repository data.
2
How do I fix CVE-2014-0488?
To mitigate CVE-2014-0488, upgrade APT to version 1.0.9 or later.
3
Which versions of APT are affected by CVE-2014-0488?
CVE-2014-0488 affects APT versions 1.0.3 and 1.0.7.
4
What type of attack does CVE-2014-0488 allow?
CVE-2014-0488 allows remote attackers to influence operations during transitions from unauthenticated to authenticated states.
5
Is there a known exploit for CVE-2014-0488?
As of now, there are no specific exploits publicly available for CVE-2014-0488, but the vulnerability's nature suggests potential risk.