CVE-2014-0490: Input Validation
Published Nov 3, 2014
·Updated
The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitrary code via a crafted package.
Affected Software
7 affected components
Debian Advanced Package Tool<=1.0.8
Debian Advanced Package Tool=1.0.3
Debian Advanced Package Tool=1.0.4
Debian Advanced Package Tool=1.0.5
Debian Advanced Package Tool=1.0.6
Debian Advanced Package Tool=1.0.7
Linux Linux kernel
Remediation
Patch Available
Event History
Nov 3, 2014
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-0490?
CVE-2014-0490 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code.
2
How do I fix CVE-2014-0490?
To fix CVE-2014-0490, update your APT package to version 1.0.9 or later.
3
Which versions of APT are affected by CVE-2014-0490?
CVE-2014-0490 affects APT versions prior to 1.0.9, including 1.0.3 through 1.0.8.
4
What type of vulnerability is CVE-2014-0490?
CVE-2014-0490 is a remote code execution vulnerability caused by improper signature validation.
5
Can CVE-2014-0490 impact Linux systems?
Yes, CVE-2014-0490 can impact Debian-based Linux systems that utilize the affected versions of APT.