Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-0214
HistoryMar 06, 2012 - 12:00 a.m.

CVE-2012-0214

2012-03-0600:00:00
ubuntu.com
ubuntu.com
10

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

35.2%

The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in
Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before
0.8.16~exp13, when updating from repositories that use InRelease files,
allows man-in-the-middle attackers to install arbitrary packages by
preventing a user from downloading the new InRelease file, which leaves the
original InRelease file active and makes it more difficult to detect that
the Packages file is modified and unsigned.

Bugs

Notes

Author Note
mdeslaur only natty+ supports InRelease
OSVersionArchitecturePackageVersionFilename
ubuntu11.04noarchapt< 0.8.13.2ubuntu4.4UNKNOWN
ubuntu11.10noarchapt< 0.8.16~exp5ubuntu13.2UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

35.2%