Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-0961
HistoryDec 12, 2012 - 12:00 a.m.

CVE-2012-0961

2012-12-1200:00:00
ubuntu.com
ubuntu.com
15

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

5.1%

Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6,
0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x
before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions
for /var/log/apt/term.log, which allows local users to obtain sensitive
shell information by reading the log file.

Bugs

Notes

Author Note
mdeslaur This was introduced in Oneiric, as the fix for bug 404724
OSVersionArchitecturePackageVersionFilename
ubuntu11.10noarchapt< 0.8.16~exp5ubuntu13.6UNKNOWN
ubuntu12.04noarchapt< 0.8.16~exp12ubuntu10.7UNKNOWN
ubuntu12.10noarchapt< 0.9.7.5ubuntu5.2UNKNOWN

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

5.1%