APT before 1.0.9 does not verify downloaded files if they have been modified as indicated using the If-Modified-Since header, which has unspecified impact and attack vectors.
Vulnerable Configurations
It was discovered that APT, the high level package manager, does not properly invalidate unauthenticated data (CVE-2014-0488), performs incorrect verification of 304 replies (CVE-2014-0487) and does not perform the checksum check when the Acquire::GzipIndexes option is used (CVE-2014-0489).
It was discovered that APT, the high level package manager, does not properly invalidate unauthenticated data (CVE-2014-0488 ), performs incorrect verification of 304 replies (CVE-2014-0487 ), does not perform the checksum check when the Acquire::GzipIndexes option is used (CVE-2014-0489 ) and does not properly perform validation for binary packages downloaded by the apt-get download command (CVE-2014-0490 ).

It was discovered that APT did not re-verify downloaded files when the If-Modified-Since wasn