Debian Security Advisory

DLA-53-1 apt -- LTS security update

Date Reported:
03 Sep 2014
Affected Packages:
apt
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2014-0487, CVE-2014-0488, CVE-2014-0489.
More information:

It was discovered that APT, the high level package manager, does not properly invalidate unauthenticated data (CVE-2014-0488), performs incorrect verification of 304 replies (CVE-2014-0487) and does not perform the checksum check when the Acquire::GzipIndexes option is used (CVE-2014-0489).

For Debian 6 Squeeze, these issues have been fixed in apt version 0.8.10.3+squeeze3