Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0489

Опубликовано: 03 нояб. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary code via a crafted package.

РелизСтатусПримечание
devel

released

1.0.8ubuntu2
esm-infra-legacy/trusty

released

1.0.1ubuntu2.3
lucid

released

0.7.25.3ubuntu9.16
precise

released

0.8.16~exp12ubuntu10.19
trusty

released

1.0.1ubuntu2.3
trusty/esm

released

1.0.1ubuntu2.3
upstream

needs-triage

Показывать по

EPSS

Процентиль: 71%
0.00688
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
больше 11 лет назад

APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary code via a crafted package.

debian
больше 11 лет назад

APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, doe ...

github
больше 3 лет назад

APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary code via a crafted package.

EPSS

Процентиль: 71%
0.00688
Низкий

7.5 High

CVSS2