CVE-2014-0478: Debian Advanced Package Tool
Medium severity, CVSS 4.0. EPSS: 1.6% chance of exploitation in the next 30 days.
APT before 1.0.4 does not properly validate source packages, which allows man-in-the-middle attackers to download and install Trojan horse packages by removing the Release signature.
Affected products
- Debian Advanced Package Tool: up to and including 1.0.3
Published 2014-06-17. Last modified 2026-06-17.