CVE-2014-6273: Debian Advanced Package Tool

Medium severity, CVSS 6.8. EPSS: 2.4% chance of exploitation in the next 30 days.

Buffer overflow in the HTTP transport code in apt-get in APT 1.0.1 and earlier allows man-in-the-middle attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted URL.

Affected products

  • Debian Advanced Package Tool: up to and including 1.0.1

Published 2014-09-30. Last modified 2026-06-17.