CVE-2014-0489: Input Validation
Published Nov 3, 2014
·Updated
APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary code via a crafted package.
Affected Software
3 affected components
Debian Advanced Package Tool=1.0.3
Debian Advanced Package Tool=1.0.5
Debian Advanced Package Tool=1.0.7
Remediation
Patch Available
Event History
Nov 3, 2014
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-0489?
CVE-2014-0489 is considered a critical vulnerability that can lead to the execution of arbitrary code.
2
How do I fix CVE-2014-0489?
To fix CVE-2014-0489, upgrade APT to version 1.0.9 or later.
3
Who is affected by CVE-2014-0489?
CVE-2014-0489 affects users of APT versions 1.0.3, 1.0.5, and 1.0.7 when the Acquire::GzipIndexes option is enabled.
4
What type of vulnerability is CVE-2014-0489?
CVE-2014-0489 is a remote code execution vulnerability due to a lack of checksum validation.
5
Can CVE-2014-0489 affect my system's security?
Yes, CVE-2014-0489 can significantly compromise system security by allowing attackers to execute arbitrary code remotely.