Canonical Software-Properties vulnerabilities
3 known vulnerabilities affecting canonical/software-properties.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2012-0955P3HIGHCVSS 7.4fixed in 0.92≥ 0.92, < 0.922020-12-02
CVE-2012-0955 [HIGH] CWE-295 CVE-2012-0955: software-properties was vulnerable to a person-in-the-middle attack due to incorrect TLS certificate
software-properties was vulnerable to a person-in-the-middle attack due to incorrect TLS certificate validation in softwareproperties/ppa.py. software-properties didn't check TLS certificates under python2 and only checked certificates under python3 if a valid certificate bundle was provided. Fixed in software-properties version 0.92.
nvdosv
CVE-2011-4407P4MEDIUMCVSS 4.3≤ 0.81.13.12014-05-14
CVE-2011-4407 [MEDIUM] CWE-20 CVE-2011-4407: ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloa
ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.
nvdosv
CVE-2013-1061P4MEDIUMCVSS 4.6≥ 0, < 0.92.182013-10-03
CVE-2013-1061 [MEDIUM] CVE-2013-1061: dbus/SoftwarePropertiesDBus
dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, 0.92.9 before 0.92.9.3, and 0.82.7 before 0.82.7.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
osv