{"id":"CVE-2014-0478","details":"APT before 1.0.4 does not properly validate source packages, which allows man-in-the-middle attackers to download and install Trojan horse packages by removing the Release signature.","modified":"2026-04-10T03:43:33.861576Z","published":"2014-06-17T14:55:06Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/58843"},{"type":"ADVISORY","url":"http://secunia.com/advisories/59358"},{"type":"ADVISORY","url":"http://www.debian.org/security/2014/dsa-2958"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-2246-1"},{"type":"EVIDENCE","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=749795"}],"schema_version":"1.7.5"}