Vulnerabilities > Debian > Advanced Package Tool > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-04-21 | CVE-2009-1358 | Unspecified vulnerability in Debian Advanced Package Tool and APT apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories. | 10.0 |
2009-04-16 | CVE-2009-1300 | Improper Input Validation vulnerability in Debian Advanced Package Tool 0.7.20 apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight. | 10.0 |