Home/Product/debian advanced package tool
Product

debian advanced package tool

22 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2020-27351
>= 1.1.0\~beta1 and < 1.1.0\~beta1ubuntu0.16.04.10
Various memory and file descriptor leaks were found in apt-python files python/arfile.cc, python/tag.cc, python/tarfile.cc, aka GH
2.0LOW
CVE-2020-27350
>= 1.2.32ubuntu0 and < 1.2.32ubuntu0.2
APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/co
5.7MEDIUM
CVE-2011-3374
all versions
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential
3.7LOW
CVE-2019-3462
< 1.2.30
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content inje
8.1HIGH
CVE-2018-0501
>= 1.6.0 and < 1.6.4
The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg
5.9MEDIUM
CVE-2016-1252
< 1.0.9.8.4
The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17
5.9MEDIUM
CVE-2014-0490
<= 1.0.8
The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers
CVE-2014-0489
all versions
APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to e
CVE-2014-0488
all versions
APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows re
CVE-2014-0487
all versions
APT before 1.0.9 does not verify downloaded files if they have been modified as indicated using the If-Modified-Since header, whic
CVE-2014-7206
<= 1.0.9.1
The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog f
CVE-2014-6273
<= 1.0.1
Buffer overflow in the HTTP transport code in apt-get in APT 1.0.1 and earlier allows man-in-the-middle attackers to cause a denia
CVE-2014-0478
<= 1.0.3
APT before 1.0.4 does not properly validate source packages, which allows man-in-the-middle attackers to download and install Troj
CVE-2012-0214
<= 0.8.16\~exp12
The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.1
CVE-2011-3634
<= 0.8.10.3
methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabl
CVE-2013-1051
all versions
apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle attackers
CVE-2012-0961
all versions
Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x
CVE-2012-3587
all versions
APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument or
CVE-2012-0954
all versions
APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument or
CVE-2011-1829
< 0.8.15.2
APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified
CVE-2009-1358
<= 0.7.20
apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid
CVE-2009-1300
all versions
apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updat
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin