CVE-2012-0961
published 2012-12-26CVE-2012-0961: Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as…
PriorityP45low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.35%
27.8th percentile
Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/apt/term.log, which allows local users to obtain sensitive shell information by reading the log file.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | advanced_package_tool | — | — |
| debian | apt | < apt 0.9.7.7 (bookworm) | apt 0.9.7.7 (bookworm) |
| debian | apt | — | — |
| debian | apt | >= 0 < 0.9.7.7 | 0.9.7.7 |
| debian | apt | >= 0 < 0.9.7.7 | 0.9.7.7 |
| debian | apt | >= 0 < 0.9.7.7 | 0.9.7.7 |
| debian | apt | >= 0 < 0.9.7.7 | 0.9.7.7 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_debian2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xq9m-84rg-77f9: Apt 0
ghsa_unreviewed·2022-05-13
CVE-2012-0961 [LOW] CWE-200 GHSA-xq9m-84rg-77f9: Apt 0
Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/apt/term.log, which allows local users to obtain sensitive shell information by reading the log file.
OSV
CVE-2012-0961: Apt 0
osv·2012-12-26·CVSS 2.1
CVE-2012-0961 [LOW] CVE-2012-0961: Apt 0
Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/apt/term.log, which allows local users to obtain sensitive shell information by reading the log file.
Ubuntu
APT vulnerability
vendor_ubuntu·2012-12-12
CVE-2012-0961 APT vulnerability
Title: APT vulnerability
Summary: APT could expose sensitive information.
It was discovered that APT set inappropriate permissions on the term.log
file. A local attacker could use this flaw to possibly obtain sensitive
information.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2012-0961: apt - Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x b...
vendor_debian·2012·CVSS 2.1
CVE-2012-0961 [LOW] CVE-2012-0961: apt - Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x b...
Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/apt/term.log, which allows local users to obtain sensitive shell information by reading the log file.
Scope: local
bookworm: resolved (fixed in 0.9.7.7)
bullseye: resolved (fixed in 0.9.7.7)
forky: resolved (fixed in 0.9.7.7)
sid: resolved (fixed in 0.9.7.7)
trixie: resolved (fixed in 0.9.7.7)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2012-12-26
Published