CVE-2014-0478: Debian Advanced Package Tool

Medium severity, CVSS 4.0. EPSS: 1.6% chance of exploitation in the next 30 days.

APT before 1.0.4 does not properly validate source packages, which allows man-in-the-middle attackers to download and install Trojan horse packages by removing the Release signature.

Affected products

  • Debian Advanced Package Tool: up to and including 1.0.3

Published 2014-06-17. Last modified 2026-06-17.