Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-3587
HistoryJun 19, 2012 - 12:00 a.m.

CVE-2012-3587

2012-06-1900:00:00
ubuntu.com
ubuntu.com
11

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

53.9%

APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key
net-update to import keyrings, relies on GnuPG argument order and does not
check GPG subkeys, which might allow remote attackers to install Trojan
horse packages via a man-in-the-middle (MITM) attack.

Bugs

Notes

Author Note
jdstrand LP: #1013639 disabled net-update. LP: #1013681 tracks the work needed to re-enable it safely
OSVersionArchitecturePackageVersionFilename
ubuntu8.04noarchapt< 0.7.9ubuntu17.6UNKNOWN
ubuntu10.04noarchapt< 0.7.25.3ubuntu9.13UNKNOWN
ubuntu11.04noarchapt< 0.8.13.2ubuntu4.6UNKNOWN
ubuntu11.10noarchapt< 0.8.16~exp5ubuntu13.5UNKNOWN
ubuntu12.04noarchapt< 0.8.16~exp12ubuntu10.2UNKNOWN

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

EPSS

0.002

Percentile

53.9%