CVE-2009-1300
Summary
| CVE | CVE-2009-1300 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-04-16 15:12:57 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Debian | Advanced Package Tool | 0.7.20 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| USN-762-1: APT vulnerabilities | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | |
| #523213 - /etc/cron.daily/apt does not check return code of date - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| Bug #354793 “date returns “invalid date” for some timezone's DST...” : Bugs : “coreutils” package : Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | bugs.launchpad.net | |
| Ubuntu update for apt - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| oss-security - CVE request: apt | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| apt Package Signature Verification Security Bypass - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-1779-1 apt | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Debian update for apt - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.