CVE-2014-0489
Publication date 16 September 2014
Last updated 24 July 2024
Ubuntu priority
APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary code via a crafted package.
Status
Package | Ubuntu Release | Status |
---|---|---|
apt | 14.04 LTS trusty |
Fixed 1.0.1ubuntu2.3
|
References
Related Ubuntu Security Notices (USN)
- USN-2348-1
- APT vulnerabilities
- 16 September 2014