Vulnerabilities > Debian > Advanced Package Tool > Critical

DATE CVE VULNERABILITY TITLE RISK
2009-04-21 CVE-2009-1358 Unspecified vulnerability in Debian Advanced Package Tool and APT
apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.
network
low complexity
debian
critical
10.0
2009-04-16 CVE-2009-1300 Improper Input Validation vulnerability in Debian Advanced Package Tool 0.7.20
apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight.
network
low complexity
debian CWE-20
critical
10.0