Name | CVE-2009-1300 |
Description | apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-1779-1, DTSA-199-1 |
Debian Bugs | 523213 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
apt (PTS) | jessie, jessie (lts) | 1.0.9.8.7 | fixed |
stretch (security), stretch (lts), stretch | 1.4.11 | fixed | |
buster | 1.8.2.3 | fixed | |
buster (security), buster (lts) | 1.8.2.2 | fixed | |
bullseye | 2.2.4 | fixed | |
bookworm | 2.6.1 | fixed | |
trixie | 2.9.10 | fixed | |
sid | 2.9.14 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
apt | source | etch | 0.6.46.4-0.1+etch1 | DSA-1779-1 | ||
apt | source | lenny | 0.7.20.2+lenny1 | DSA-1779-1 | ||
apt | source | squeeze | 0.7.20.2+squeeze1 | DTSA-199-1 | ||
apt | source | (unstable) | 0.7.21 | 523213 |