Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x6q8-2q34-2w6w

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary code via a crafted package.

APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary code via a crafted package.

EPSS

Процентиль: 71%
0.00688
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 11 лет назад

APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary code via a crafted package.

nvd
больше 11 лет назад

APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary code via a crafted package.

debian
больше 11 лет назад

APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, doe ...

EPSS

Процентиль: 71%
0.00688
Низкий

Дефекты

CWE-20