CVE-2012-0214
published 2014-04-15CVE-2012-0214: The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before 0.8.16~exp13, when…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.33%
68.0th percentile
The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before 0.8.16~exp13, when updating from repositories that use InRelease files, allows man-in-the-middle attackers to install arbitrary packages by preventing a user from downloading the new InRelease file, which leaves the original InRelease file active and makes it more difficult to detect that the Packages file is modified and unsigned.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| advanced_package_tool | advanced_package_tool | <= 0.8.16\~exp12 | — |
| advanced_package_tool | advanced_package_tool | — | — |
| advanced_package_tool | advanced_package_tool | — | — |
| advanced_package_tool | advanced_package_tool | — | — |
| advanced_package_tool | advanced_package_tool | — | — |
| advanced_package_tool | advanced_package_tool | — | — |
| debian | apt | < apt 0.8.15.10 (bookworm) | apt 0.8.15.10 (bookworm) |
| debian | apt | >= 0 < 0.8.15.10 | 0.8.15.10 |
| debian | apt | >= 0 < 0.8.15.10 | 0.8.15.10 |
| debian | apt | >= 0 < 0.8.15.10 | 0.8.15.10 |
| debian | apt | >= 0 < 0.8.15.10 | 0.8.15.10 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5h75-gqf7-227h: The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item
ghsa_unreviewed·2022-05-04
CVE-2012-0214 [MEDIUM] GHSA-5h75-gqf7-227h: The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item
The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before 0.8.16~exp13, when updating from repositories that use InRelease files, allows man-in-the-middle attackers to install arbitrary packages by preventing a user from downloading the new InRelease file, which leaves the original InRelease file active and makes it more difficult to detect that the Packages file is modified and unsigned.
OSV
CVE-2012-0214: The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item
osv·2014-04-15·CVSS 4.3
CVE-2012-0214 [MEDIUM] CVE-2012-0214: The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item
The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before 0.8.16~exp13, when updating from repositories that use InRelease files, allows man-in-the-middle attackers to install arbitrary packages by preventing a user from downloading the new InRelease file, which leaves the original InRelease file active and makes it more difficult to detect that the Packages file is modified and unsigned.
Ubuntu
APT vulnerability
vendor_ubuntu·2012-03-06
CVE-2012-0214 APT vulnerability
Title: APT vulnerability
Summary: An attacker could trick APT into installing altered packages.
Simon Ruderich discovered that APT incorrectly handled repositories that
use InRelease files. The default Ubuntu repositories do not use InRelease
files, so this issue only affected third-party repositories. If a remote
attacker were able to perform a machine-in-the-middle attack, this flaw could
potentially be used to install altered packages.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2012-0214: apt - The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Pac...
vendor_debian·2012·CVSS 4.3
CVE-2012-0214 [MEDIUM] CVE-2012-0214: apt - The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Pac...
The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before 0.8.16~exp13, when updating from repositories that use InRelease files, allows man-in-the-middle attackers to install arbitrary packages by preventing a user from downloading the new InRelease file, which leaves the original InRelease file active and makes it more difficult to detect that the Packages file is modified and unsigned.
Scope: local
bookworm: resolved (fixed in 0.8.15.10)
bullseye: resolved (fixed in 0.8.15.10)
forky: resolved (fixed in 0.8.15.10)
sid: resolved (fixed in 0.8.15.10)
trixie: resolved (fixed in 0.8.15.10)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://anonscm.debian.org/gitweb/?p=apt/apt.git%3Ba=commitdiff%3Bh=b7a6594d1e5ed199a7a472b78b33e070375d6f92http://anonscm.debian.org/gitweb/?p=apt/apt.git%3Ba=commitdiff%3Bh=de498a528cd6fc36c4bb22bf8dec6558e21cc9b6http://www.ubuntu.com/usn/USN-1385-1http://anonscm.debian.org/gitweb/?p=apt/apt.git%3Ba=commitdiff%3Bh=b7a6594d1e5ed199a7a472b78b33e070375d6f92http://anonscm.debian.org/gitweb/?p=apt/apt.git%3Ba=commitdiff%3Bh=de498a528cd6fc36c4bb22bf8dec6558e21cc9b6http://www.ubuntu.com/usn/USN-1385-1
2014-04-15
Published