Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-0214

Опубликовано: 15 апр. 2014
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before 0.8.16~exp13, when updating from repositories that use InRelease files, allows man-in-the-middle attackers to install arbitrary packages by preventing a user from downloading the new InRelease file, which leaves the original InRelease file active and makes it more difficult to detect that the Packages file is modified and unsigned.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:advanced_package_tool:advanced_package_tool:*:*:*:*:*:*:*:*
Версия до 0.8.16\~exp12 (включая)
cpe:2.3:a:advanced_package_tool:advanced_package_tool:0.8.11:*:*:*:*:*:*:*
cpe:2.3:a:advanced_package_tool:advanced_package_tool:0.8.12:*:*:*:*:*:*:*
cpe:2.3:a:advanced_package_tool:advanced_package_tool:0.8.13:*:*:*:*:*:*:*
cpe:2.3:a:advanced_package_tool:advanced_package_tool:0.8.14:*:*:*:*:*:*:*
cpe:2.3:a:advanced_package_tool:advanced_package_tool:0.8.15:*:*:*:*:*:*:*

EPSS

Процентиль: 31%
0.00118
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
почти 12 лет назад

The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before 0.8.16~exp13, when updating from repositories that use InRelease files, allows man-in-the-middle attackers to install arbitrary packages by preventing a user from downloading the new InRelease file, which leaves the original InRelease file active and makes it more difficult to detect that the Packages file is modified and unsigned.

debian
почти 12 лет назад

The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Ad ...

github
почти 4 года назад

The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before 0.8.16~exp13, when updating from repositories that use InRelease files, allows man-in-the-middle attackers to install arbitrary packages by preventing a user from downloading the new InRelease file, which leaves the original InRelease file active and makes it more difficult to detect that the Packages file is modified and unsigned.

EPSS

Процентиль: 31%
0.00118
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-264