CVE Vulnerabilities

CVE-2012-0944

Improper Authentication

Published: Jun 04, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is not simulated, which allows remote attackers to install arbitrary packages via a man-in-the-middle attack.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
AptdaemonSebastian_heinlein*0.42 (including)
AptdaemonSebastian_heinlein0.20 (including)0.20 (including)
AptdaemonSebastian_heinlein0.30 (including)0.30 (including)
AptdaemonSebastian_heinlein0.31 (including)0.31 (including)
AptdaemonSebastian_heinlein0.32 (including)0.32 (including)
AptdaemonSebastian_heinlein0.33 (including)0.33 (including)
AptdaemonSebastian_heinlein0.34 (including)0.34 (including)
AptdaemonSebastian_heinlein0.40 (including)0.40 (including)
AptdaemonSebastian_heinlein0.41 (including)0.41 (including)
Ubuntu_linuxCanonical11.04 (including)11.04 (including)
Ubuntu_linuxCanonical11.10 (including)11.10 (including)
Ubuntu_linuxCanonical12.04-lts (including)12.04-lts (including)
AptdaemonUbuntudevel*
AptdaemonUbuntunatty*
AptdaemonUbuntuoneiric*

Potential Mitigations

References