CVE-2014-7206: Low severity kali linux package management (apt) vulnerability
Published Oct 2, 2014
·Updated
The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.
Affected Software
7 affected componentsFixes available
debian/apt
2.2.42.6.12.9.7
Debian Advanced Package Tool<=1.0.9.1
Debian Advanced Package Tool=1.0.8
Debian Apt=0.9.7.9-ubunto3
Debian Apt=0.9.7.9-ubunto4
Debian Apt=0.9.7.9-ubunto5
Debian Apt=1.0.9
Event History
Oct 2, 2014
Data Sourced
04:33 PM
SeverityAffected Software
Oct 15, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-7206?
CVE-2014-7206 is classified as a moderate severity vulnerability due to its impact on local users.
2
How do I fix CVE-2014-7206?
To fix CVE-2014-7206, upgrade to a version of Apt that is newer than 1.0.9.1.
3
What type of attack does CVE-2014-7206 involve?
CVE-2014-7206 involves a symlink attack that allows local users to manipulate file writes.
4
Which versions of Apt are affected by CVE-2014-7206?
Versions of Apt prior to 1.0.9.2 are affected by CVE-2014-7206.
5
Can I exploit CVE-2014-7206 remotely?
CVE-2014-7206 cannot be exploited remotely as it requires local access to the system.