CVE-2014-7206

low
Published 2014-10-15 · Modified 2026-05-06
CVSS v3
CVSS v2
3.6
VIR risk
3.6

Description

The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://www.ubuntu.com/usn/USN-2370-1

vendor Authored 2026-05-27

Vendor advisory: security@debian.org — http://www.debian.org/security/2014/dsa-3048

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-7206

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.0.9.2
debian debianbullseyefixed1.0.9.2
debian debianforkyfixed1.0.9.2
debian debiansidfixed1.0.9.2
debian debiantrixiefixed1.0.9.2

Application impact

VendorProductVersionsFixed
debianadvanced_package_tool{"endIncluding":"1.0.9.1"}
debianadvanced_package_tool1.0.8
debianapt0.9.7.9
debianapt1.0.9

References

CWEs

CWE-59

Verify integrity in audit chain (admin only). AS-IS.