« Volver al listado

CVE-2014-0487

Estado: ModificadaAlta (7.5)—

APT before 1.0.9 does not verify downloaded files if they have been modified as indicated using the If-Modified-Since header, which has unspecified impact and attack vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-0487",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": true,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "security@debian.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-11-03T22:55:07.303",
  "references": [
    {
      "url": "http://secunia.com/advisories/61275",
      "source": "security@debian.org"
    },
    {
      "url": "http://secunia.com/advisories/61286",
      "source": "security@debian.org"
    },
    {
      "url": "http://ubuntu.com/usn/usn-2348-1",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@debian.org"
    },
    {
      "url": "http://www.debian.org/security/2014/dsa-3025",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@debian.org"
    },
    {
      "url": "http://secunia.com/advisories/61275",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/61286",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://ubuntu.com/usn/usn-2348-1",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2014/dsa-3025",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "APT before 1.0.9 does not verify downloaded files if they have been modified as indicated using the If-Modified-Since header, which has unspecified impact and attack vectors."
    },
    {
      "lang": "es",
      "value": "APT anterior a 1.0.9 no verifica ficheros descargados si han sido modificados como indica utilizando la cabecera If-Modified-Since, lo que tiene un impacto y vectores de ataque no especificados."
    }
  ],
  "lastModified": "2026-06-17T00:03:08.073",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:debian:advanced_package_tool:1.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B3D0444-F401-4A5A-9825-8CEECF37CFE7"
            },
            {
              "criteria": "cpe:2.3:a:debian:advanced_package_tool:1.0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1AE05C16-DD11-4B09-A617-0C23D4A47D1E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@debian.org"
}