VendorsDebianadvanced_package_tool0.7.20
Vulnerabilities

Debian Advanced Package Tool 0.7.20

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2009-1300
apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight.
Published 2009-04-16 · Modified
10.0EPSS 0.019
CVE-2012-0954
APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install altered packages via a man-in-the-middle (MITM) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3587.
Published 2012-06-19 · Modified
2.6EPSS 0.022
CVE-2012-3587
APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install Trojan horse packages via a man-in-the-middle (MITM) attack.
Published 2012-06-19 · Modified
2.6EPSS 0.017