{"id":"CVE-2014-7206","details":"The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.","modified":"2026-04-10T03:44:01.213727Z","published":"2014-10-15T14:55:09Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/61158"},{"type":"ADVISORY","url":"http://secunia.com/advisories/61333"},{"type":"ADVISORY","url":"http://secunia.com/advisories/61768"},{"type":"ADVISORY","url":"http://www.debian.org/security/2014/dsa-3048"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-2370-1"},{"type":"WEB","url":"http://www.securityfocus.com/bid/70310"},{"type":"WEB","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=763780"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/96951"}],"schema_version":"1.7.5"}