CVE-2014-7206: Debian Advanced Package Tool

Low severity, CVSS 3.6. EPSS: 0.4% chance of exploitation in the next 30 days.

The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.

Affected products

  • Debian Advanced Package Tool: up to and including 1.0.9.1; version 1.0.8 only
  • Debian Apt: version 0.9.7.9 only; version 1.0.9 only

Published 2014-10-15. Last modified 2026-06-17.