Debian Security Advisory
DLA-53-1 apt -- LTS security update
- Date Reported:
- 03 Sep 2014
- Affected Packages:
- apt
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2014-0487, CVE-2014-0488, CVE-2014-0489.
- More information:
-
It was discovered that APT, the high level package manager, does not properly invalidate unauthenticated data (CVE-2014-0488), performs incorrect verification of 304 replies (CVE-2014-0487) and does not perform the checksum check when the Acquire::GzipIndexes option is used (CVE-2014-0489).
For Debian 6
Squeeze
, these issues have been fixed in apt version 0.8.10.3+squeeze3