The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.
| Software | From | Fixed in |
|---|---|---|
| debian / apt | 0.9.7.9-ubunto5 | 0.9.7.9-ubunto5.x |
| debian / apt | 0.9.7.9-ubunto4 | 0.9.7.9-ubunto4.x |
| debian / apt | 1.0.9 | 1.0.9.x |
| debian / apt | 0.9.7.9-ubunto3 | 0.9.7.9-ubunto3.x |
| debian / advanced_package_tool | 1.0.8 | 1.0.8.x |
| debian / advanced_package_tool | - | 1.0.9.1.x |