Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-0214

Опубликовано: 15 апр. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3

Описание

The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before 0.8.16~exp13, when updating from repositories that use InRelease files, allows man-in-the-middle attackers to install arbitrary packages by preventing a user from downloading the new InRelease file, which leaves the original InRelease file active and makes it more difficult to detect that the Packages file is modified and unsigned.

РелизСтатусПримечание
devel

released

0.8.16~exp12ubuntu5
hardy

not-affected

lucid

not-affected

maverick

not-affected

natty

released

0.8.13.2ubuntu4.4
oneiric

released

0.8.16~exp5ubuntu13.2
upstream

needs-triage

Показывать по

EPSS

Процентиль: 31%
0.00118
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before 0.8.16~exp13, when updating from repositories that use InRelease files, allows man-in-the-middle attackers to install arbitrary packages by preventing a user from downloading the new InRelease file, which leaves the original InRelease file active and makes it more difficult to detect that the Packages file is modified and unsigned.

debian
почти 12 лет назад

The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Ad ...

github
почти 4 года назад

The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before 0.8.16~exp13, when updating from repositories that use InRelease files, allows man-in-the-middle attackers to install arbitrary packages by preventing a user from downloading the new InRelease file, which leaves the original InRelease file active and makes it more difficult to detect that the Packages file is modified and unsigned.

EPSS

Процентиль: 31%
0.00118
Низкий

4.3 Medium

CVSS2