VYPR
Unrated severityNVD Advisory· Published Nov 3, 2014· Updated May 6, 2026

CVE-2014-0488

CVE-2014-0488

Description

APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to have unspecified impact via crafted repository data.

Affected products

2
  • cpe:2.3:a:debian:advanced_package_tool:1.0.3:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:debian:advanced_package_tool:1.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:debian:advanced_package_tool:1.0.7:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.