CVE-2014-7206
published 2014-10-15CVE-2014-7206: The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.
PriorityP414low3.6CVSS 2.0
AVLACLAuNCNIPAP
EPSS
0.39%
30.7th percentile
The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | advanced_package_tool | <= 1.0.9.1 | — |
| debian | advanced_package_tool | — | — |
| debian | apt | < apt 1.0.9.2 (bookworm) | apt 1.0.9.2 (bookworm) |
| debian | apt | — | — |
| debian | apt | — | — |
| debian | apt | >= 0 < 1.0.9.2 | 1.0.9.2 |
| debian | apt | >= 0 < 1.0.9.2 | 1.0.9.2 |
| debian | apt | >= 0 < 1.0.9.2 | 1.0.9.2 |
| debian | apt | >= 0 < 1.0.9.2 | 1.0.9.2 |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv3.6LOW
vendor_debian3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pvf6-chpc-2vfx: The changelog command in Apt before 1
ghsa_unreviewed·2022-05-13
CVE-2014-7206 [LOW] CWE-59 GHSA-pvf6-chpc-2vfx: The changelog command in Apt before 1
The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.
OSV
CVE-2014-7206: The changelog command in Apt before 1
osv·2014-10-15·CVSS 3.6
CVE-2014-7206 [LOW] CVE-2014-7206: The changelog command in Apt before 1
The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.
Ubuntu
APT vulnerability
vendor_ubuntu·2014-10-08
CVE-2014-7206 APT vulnerability
Title: APT vulnerability
Summary: APT could be made to overwrite files.
Guillem Jover discovered that APT incorrectly created a temporary file when
handling the changelog command. A local attacker could use this issue to
overwrite arbitrary files. In the default installation of Ubuntu, this
should be prevented by the kernel link restrictions.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2014-7206: apt - The changelog command in Apt before 1.0.9.2 allows local users to write to arbit...
vendor_debian·2014·CVSS 3.6
CVE-2014-7206 [LOW] CVE-2014-7206: apt - The changelog command in Apt before 1.0.9.2 allows local users to write to arbit...
The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.
Scope: local
bookworm: resolved (fixed in 1.0.9.2)
bullseye: resolved (fixed in 1.0.9.2)
forky: resolved (fixed in 1.0.9.2)
sid: resolved (fixed in 1.0.9.2)
trixie: resolved (fixed in 1.0.9.2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/61158http://secunia.com/advisories/61333http://secunia.com/advisories/61768http://www.debian.org/security/2014/dsa-3048http://www.securityfocus.com/bid/70310http://www.ubuntu.com/usn/USN-2370-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=763780https://exchange.xforce.ibmcloud.com/vulnerabilities/96951http://secunia.com/advisories/61158http://secunia.com/advisories/61333http://secunia.com/advisories/61768http://www.debian.org/security/2014/dsa-3048http://www.securityfocus.com/bid/70310http://www.ubuntu.com/usn/USN-2370-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=763780https://exchange.xforce.ibmcloud.com/vulnerabilities/96951
2014-10-15
Published