Vulnerabilities > Debian > Advanced Package Tool > Low

DATE CVE VULNERABILITY TITLE RISK
2020-12-10 CVE-2020-27351 Missing Release of Resource after Effective Lifetime vulnerability in Debian Advanced Package Tool
Various memory and file descriptor leaks were found in apt-python files python/arfile.cc, python/tag.cc, python/tarfile.cc, aka GHSL-2020-170.
local
low complexity
debian CWE-772
2.1
2014-10-15 CVE-2014-7206 Link Following vulnerability in Debian Advanced Package Tool and APT
The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.
local
low complexity
debian CWE-59
3.6
2012-12-26 CVE-2012-0961 Information Exposure vulnerability in Debian Advanced Package Tool and APT
Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/apt/term.log, which allows local users to obtain sensitive shell information by reading the log file.
local
low complexity
debian CWE-200
2.1
2012-06-19 CVE-2012-0954 Improper Input Validation vulnerability in Debian Advanced Package Tool
APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install altered packages via a man-in-the-middle (MITM) attack.
network
high complexity
debian CWE-20
2.6
2012-06-19 CVE-2012-3587 Improper Input Validation vulnerability in Debian Advanced Package Tool
APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install Trojan horse packages via a man-in-the-middle (MITM) attack.
network
high complexity
debian CWE-20
2.6