cbcvebase.
CVE-2009-1300
published 2009-04-16

CVE-2009-1300: apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which…

PriorityP337critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
1.86%
76.8th percentile
apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianadvanced_package_tool
debianapt< apt 0.7.21 (bookworm)apt 0.7.21 (bookworm)
debianapt>= 0 < 0.7.210.7.21
debianapt>= 0 < 0.7.210.7.21
debianapt>= 0 < 0.7.210.7.21
debianapt>= 0 < 0.7.210.7.21

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.