Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0490

Опубликовано: 03 нояб. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitrary code via a crafted package.

РелизСтатусПримечание
devel

released

1.0.8ubuntu2
esm-infra-legacy/trusty

released

1.0.1ubuntu2.3
lucid

released

0.7.25.3ubuntu9.16
precise

released

0.8.16~exp12ubuntu10.19
trusty

released

1.0.1ubuntu2.3
trusty/esm

released

1.0.1ubuntu2.3
upstream

needs-triage

Показывать по

EPSS

Процентиль: 71%
0.00688
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
больше 11 лет назад

The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitrary code via a crafted package.

debian
больше 11 лет назад

The apt-get download command in APT before 1.0.9 does not properly val ...

github
больше 3 лет назад

The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitrary code via a crafted package.

EPSS

Процентиль: 71%
0.00688
Низкий

7.5 High

CVSS2