CVE-2014-0478
Publication date 12 June 2014
Last updated 24 July 2024
Ubuntu priority
Description
APT before 1.0.4 does not properly validate source packages, which allows man-in-the-middle attackers to download and install Trojan horse packages by removing the Release signature.
References
Related Ubuntu Security Notices (USN)
- USN-2246-1
- APT vulnerability
- 17 June 2014