Ubuntu 10.04 LTS / 12.04 LTS / 14.04 LTS : apt vulnerabilities (USN-2348-1)

Ubuntu Security Notice (C) 2014-2016 Canonical, Inc. / NASL script (C) 2014-2016 Tenable Network Security, Inc.


Synopsis :

The remote Ubuntu host is missing a security-related patch.

Description :

It was discovered that APT did not re-verify downloaded files when the
If-Modified-Since wasn't met. (CVE-2014-0487)

It was discovered that APT did not invalidate repository data when it
switched from an unauthenticated to an authenticated state.
(CVE-2014-0488)

It was discovered that the APT Acquire::GzipIndexes option caused APT
to skip checksum validation. This issue only applied to Ubuntu 12.04
LTS and Ubuntu 14.04 LTS, and was not enabled by default.
(CVE-2014-0489)

It was discovered that APT did not correctly validate signatures when
downloading source packages using the download command. This issue
only applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-0490).

Note that Tenable Network Security has extracted the preceding
description block directly from the Ubuntu security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

Solution :

Update the affected apt package.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)

Family: Ubuntu Local Security Checks

Nessus Plugin ID: 77726 ()

Bugtraq ID:

CVE ID: CVE-2014-0487
CVE-2014-0488
CVE-2014-0489
CVE-2014-0490

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now