CVE-2014-6273: Buffer Overflow
Published Sep 30, 2014
·Updated
Buffer overflow in the HTTP transport code in apt-get in APT 1.0.1 and earlier allows man-in-the-middle attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted URL.
Affected Software
1 affected component
Debian Advanced Package Tool<=1.0.1
Remediation
Patch Available
Event History
Sep 30, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6273?
CVE-2014-6273 is classified as a high severity vulnerability due to its potential to cause denial of service and arbitrary code execution.
2
How do I fix CVE-2014-6273?
To mitigate CVE-2014-6273, upgrade to a version of APT newer than 1.0.1.
3
Which versions of APT are affected by CVE-2014-6273?
CVE-2014-6273 affects APT 1.0.1 and earlier versions.
4
What type of attack is enabled by CVE-2014-6273?
CVE-2014-6273 allows man-in-the-middle attackers to exploit the vulnerability through crafted URLs.
5
What systems are primarily impacted by CVE-2014-6273?
Debian systems using the Advanced Package Tool (APT) version 1.0.1 and earlier are primarily impacted by CVE-2014-6273.