Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian: DSA-3032-2 Urgent: APT Buffer Overflow Vulnerability Found

debian
Calendar Grey September 23, 2014
Debian Logo
Fedora Security Notification FSA-2123-2 highlights a severe DNS cache poisoning vulnerability; upgrade dnf immediately!
The Google Security Team discovered a buffer overflow vulnerability in the HTTP transport code in apt-get

Summary

Two regression fixes were included in this update:

* Fix regression from the previous update in DSA-3025-1 when the custom
apt configuration option for Dir::state::lists is set to a relative
path (#762160).

* Fix regression in the reverificaiton handling of cdrom: sources that
may lead to incorrect hashsum warnings. Affected users need to run
"apt-cdrom add" again after the update was applied.

For the stable distribution (wheezy), this problem has been fixed in
version 0.9.7.9+deb7u5.

We recommend that you upgrade your apt packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: apt
CVE ID: CVE-2014-6273

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here