CVE-2012-0962
published 2012-12-26CVE-2012-0962: Aptdaemon 0.43 in Ubuntu 11.10 and 12.04 LTS uses short IDs when importing PPA GPG keys from a keyserver, which allows remote attackers to install arbitrary…
PriorityP426medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.80%
76.3th percentile
Aptdaemon 0.43 in Ubuntu 11.10 and 12.04 LTS uses short IDs when importing PPA GPG keys from a keyserver, which allows remote attackers to install arbitrary package repository GPG keys via a man-in-the-middle (MITM) attack.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| sebastian_heinlein | aptdaemon | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mm8c-h4vv-7fr2: Aptdaemon 0
ghsa_unreviewed·2022-05-17
CVE-2012-0962 [MEDIUM] GHSA-mm8c-h4vv-7fr2: Aptdaemon 0
Aptdaemon 0.43 in Ubuntu 11.10 and 12.04 LTS uses short IDs when importing PPA GPG keys from a keyserver, which allows remote attackers to install arbitrary package repository GPG keys via a man-in-the-middle (MITM) attack.
Ubuntu
Aptdaemon vulnerability
vendor_ubuntu·2012-12-17
CVE-2012-0962 Aptdaemon vulnerability
Title: Aptdaemon vulnerability
Summary: Aptdaemon could be tricked into installing arbitrary PPA GPG keys.
It was discovered that Aptdaemon incorrectly validated PPA GPG keys when
importing from a keyserver. If a remote attacker were able to perform a
machine-in-the-middle attack, this flaw could be exploited to install altered
package repository GPG keys.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/51627http://www.securityfocus.com/bid/56959http://www.securitytracker.com/id?1027891http://www.ubuntu.com/usn/USN-1666-1https://bugs.launchpad.net/software-center-agent/%2Bbug/1052789http://secunia.com/advisories/51627http://www.securityfocus.com/bid/56959http://www.securitytracker.com/id?1027891http://www.ubuntu.com/usn/USN-1666-1https://bugs.launchpad.net/software-center-agent/%2Bbug/1052789
2012-12-26
Published