{"id":"MGASA-2014-0442","summary":"Updated apt packages fix security vulnerability","details":"The Google Security Team discovered a buffer overflow vulnerability in the\nHTTP transport code in apt-get. An attacker able to man-in-the-middle a HTTP\nrequest to an apt repository can trigger the buffer overflow, leading to a\ncrash of the \"http\" apt method binary, or potentially to arbitrary code\nexecution (CVE-2014-6273).\n\nAlso fixed is parsing of Mageia package index \"synthesis\" files with lines\nlonger than 64k characters. This is necessary for upgrading to the \"cauldron\"\ndevelopment distro that will become Mageia 5. Note however that upgrading from\nMageia 3 to Mageia 5 will not be supported.\n","modified":"2026-04-16T06:24:51.541028777Z","published":"2014-11-12T09:56:47Z","upstream":["CVE-2014-6273"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0442.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=14112"},{"type":"WEB","url":"http://www.ubuntu.com/usn/usn-2353-1/"}],"affected":[{"package":{"name":"apt","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/apt?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.5.15lorg3.94-9.2.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0442.json"}},{"package":{"name":"apt","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/apt?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.5.15lorg3.94-11.2.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0442.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}