Advanced Package Tool

Vendor:

First CVE: Apr 16, 2009 · Active for 17 years

21
Total CVEs
More Total CVEs than 94% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Advanced Package Tool over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 16, 2009
17 years ago
Most Recent CVE
Dec 10, 2020
2,052 days ago

CVE Severity & Scoring

Advanced Package Tool21 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local2 (9.5%)
Network4 (19.0%)
Unknown15 (71.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (9.5%)
High4 (19.0%)
Unknown15 (71.4%)
User Interaction
None5 (23.8%)
Unknown15 (71.4%)
Required1 (4.8%)
Privileges Required
Low1 (4.8%)
High1 (4.8%)
None4 (19.0%)
Unknown15 (71.4%)

Top CVEs

Signals from CVEs in this product scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to r
Jan 28, 20198.135NONO
The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and
Dec 5, 20175.930NOYES
apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has b
Apr 21, 200910.026NONO
apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight.
Apr 16, 200910.025NONO
Buffer overflow in the HTTP transport code in apt-get in APT 1.0.1 and earlier allows man-in-the-middle attackers to cause a denial of service (crash) or possibly execute arbitrary
Sep 30, 20146.824NONO
The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verification for the InRelease file of
Aug 21, 20185.922NONO
The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitrary code via a crafted package.
Nov 3, 20147.522NONO
APT had several integer overflows and underflows while parsing .deb packages, aka GHSL-2020-168 GHSL-2020-169, in files apt-pkg/contrib/extracttar.cc, apt-pkg/deb/debfile.cc, and a
Dec 10, 20205.721NONO
APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary code via a crafted package.
Nov 3, 20147.520NONO
APT before 1.0.9 does not verify downloaded files if they have been modified as indicated using the If-Modified-Since header, which has unspecified impact and attack vectors.
Nov 3, 20147.520NONO

Exploit Exposure

Signals from CVEs in this product scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.8% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (21 CVEs).

Media Mentions

Signals from CVEs in this product scope (21 CVEs).

Top CNAs Publishing CVEs For Advanced Package Tool

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.7.015.90.9%00
1.0.813.60.4%00
1.0.747.32.8%00
1.0.617.53.6%00
1.0.527.53.6%00
1.0.417.53.6%00
1.0.347.32.8%00
0.8.1623.20.9%00
0.8.15.922.62.0%00
0.8.15.822.62.0%00
0.8.15.722.62.0%00
0.8.15.622.62.0%00
0.8.15.1022.62.0%00
0.8.15.122.62.0%00
0.8.1522.62.0%00
0.8.14.122.62.0%00
0.8.1422.62.0%00
0.8.13.222.62.0%00
0.8.13.122.62.0%00
0.8.1322.62.0%00