CVE-2014-0488: Debian Advanced Package Tool

Medium severity, CVSS 6.8. EPSS: 2.1% chance of exploitation in the next 30 days.

APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to have unspecified impact via crafted repository data.

Affected products

  • Debian Advanced Package Tool: version 1.0.3 only; version 1.0.7 only

Published 2014-11-03. Last modified 2026-06-17.