CVE-2014-0478

Publication date 12 June 2014

Last updated 24 July 2024


Ubuntu priority

APT before 1.0.4 does not properly validate source packages, which allows man-in-the-middle attackers to download and install Trojan horse packages by removing the Release signature.

Status

Package Ubuntu Release Status
apt 14.04 LTS trusty
Fixed 1.0.1ubuntu2.1
13.10 saucy
Fixed 0.9.9.1~ubuntu3.2
12.04 LTS precise
Fixed 0.8.16~exp12ubuntu10.17
10.04 LTS lucid
Fixed 0.7.25.3ubuntu9.15

References

Related Ubuntu Security Notices (USN)

Other references