CVE-2014-0490
Publication date 16 September 2014
Last updated 24 July 2024
Ubuntu priority
The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitrary code via a crafted package.
Status
Package | Ubuntu Release | Status |
---|---|---|
apt | 14.04 LTS trusty |
Fixed 1.0.1ubuntu2.3
|
References
Related Ubuntu Security Notices (USN)
- USN-2348-1
- APT vulnerabilities
- 16 September 2014