APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to have unspecified impact via crafted repository data.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: debian

Published: 2014-11-03T22:00:00

Updated: 2024-08-06T09:20:18.468Z

Reserved: 2013-12-19T00:00:00

Link: CVE-2014-0488

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2014-11-03T22:55:07.350

Modified: 2020-01-08T15:22:51.723

Link: CVE-2014-0488

cve-icon Redhat

No data.