← Voltar para CVEs
CVE-2012-5356
N/ADescricao
The apt-add-repository tool in Ubuntu Software Properties 0.75.x before 0.75.10.3, 0.80.x before 0.80.9.2, 0.81.x before 0.81.13.5, 0.82.x before 0.82.7.3, and 0.92.x before 0.92.8 does not properly check PPA GPG keys imported from a keyserver, which allows remote attackers to install arbitrary package repository GPG keys via a man-in-the-middle (MITM) attack.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado10/10/2012
Ultima modificacao4/11/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
canonical:ubuntu_software_properties
Fraquezas (CWE)
CWE-20
Referencias
http://www.securityfocus.com/bid/55736(cve@mitre.org)
http://www.ubuntu.com/usn/USN-1588-1(cve@mitre.org)
https://exchange.xforce.ibmcloud.com/vulnerabilities/78990(cve@mitre.org)
http://www.securityfocus.com/bid/55736(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-1588-1(af854a3a-2127-422b-91ae-364da2661108)
https://bugs.launchpad.net/ubuntu/+source/software-properties/+bug/1016643(af854a3a-2127-422b-91ae-364da2661108)
https://exchange.xforce.ibmcloud.com/vulnerabilities/78990(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.