CVE-2014-6273

Publication date 23 September 2014

Last updated 24 July 2024


Ubuntu priority

Buffer overflow in the HTTP transport code in apt-get in APT 1.0.1 and earlier allows man-in-the-middle attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted URL.

Read the notes from the security team

Status

Package Ubuntu Release Status
apt 14.04 LTS trusty
Fixed 1.0.1ubuntu2.4.1
12.04 LTS precise
Fixed 0.8.16~exp12ubuntu10.20.1
10.04 LTS lucid
Fixed 0.7.25.3ubuntu9.17.1

Notes


mdeslaur

should only be a denial of service because of hardening

References

Related Ubuntu Security Notices (USN)

Other references