CVE-2012-0944
published 2012-06-04CVE-2012-0944: Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is not simulated, which allows remote…
PriorityP424medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.21%
65.5th percentile
Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is not simulated, which allows remote attackers to install arbitrary packages via a man-in-the-middle attack.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| sebastian_heinlein | aptdaemon | <= 0.42 | — |
| sebastian_heinlein | aptdaemon | — | — |
| sebastian_heinlein | aptdaemon | — | — |
| sebastian_heinlein | aptdaemon | — | — |
| sebastian_heinlein | aptdaemon | — | — |
| sebastian_heinlein | aptdaemon | — | — |
| sebastian_heinlein | aptdaemon | — | — |
| sebastian_heinlein | aptdaemon | — | — |
| sebastian_heinlein | aptdaemon | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-363x-qxhw-jjx9: Aptdaemon 0
ghsa_unreviewed·2022-05-17
CVE-2012-0944 [MEDIUM] CWE-287 GHSA-363x-qxhw-jjx9: Aptdaemon 0
Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is not simulated, which allows remote attackers to install arbitrary packages via a man-in-the-middle attack.
Ubuntu
Aptdaemon vulnerability
vendor_ubuntu·2012-04-02
CVE-2012-0944 Aptdaemon vulnerability
Title: Aptdaemon vulnerability
Summary: An attacker could trick Aptdaemon into installing altered packages.
It was discovered that Aptdaemon incorrectly handled installing packages
without performing a transaction simulation. An attacker could possibly use
this flaw to install altered packages.
Instructions: In general, a standard system update will make all the necessary changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/48688http://ubuntu.com/usn/usn-1414-1http://www.osvdb.org/80887http://www.securityfocus.com/bid/52855https://bugs.launchpad.net/ubuntu/%2Bsource/aptdaemon/%2Bbug/959131https://exchange.xforce.ibmcloud.com/vulnerabilities/74553http://secunia.com/advisories/48688http://ubuntu.com/usn/usn-1414-1http://www.osvdb.org/80887http://www.securityfocus.com/bid/52855https://bugs.launchpad.net/ubuntu/%2Bsource/aptdaemon/%2Bbug/959131https://exchange.xforce.ibmcloud.com/vulnerabilities/74553
2012-06-04
Published