CVE Vulnerabilities

CVE-2012-0944

Improper Authentication

Published: Jun 04, 2012 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is not simulated, which allows remote attackers to install arbitrary packages via a man-in-the-middle attack.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Aptdaemon Sebastian_heinlein * 0.42 (including)
Aptdaemon Sebastian_heinlein 0.20 (including) 0.20 (including)
Aptdaemon Sebastian_heinlein 0.30 (including) 0.30 (including)
Aptdaemon Sebastian_heinlein 0.31 (including) 0.31 (including)
Aptdaemon Sebastian_heinlein 0.32 (including) 0.32 (including)
Aptdaemon Sebastian_heinlein 0.33 (including) 0.33 (including)
Aptdaemon Sebastian_heinlein 0.34 (including) 0.34 (including)
Aptdaemon Sebastian_heinlein 0.40 (including) 0.40 (including)
Aptdaemon Sebastian_heinlein 0.41 (including) 0.41 (including)
Ubuntu_linux Canonical 11.04 (including) 11.04 (including)
Ubuntu_linux Canonical 11.10 (including) 11.10 (including)
Ubuntu_linux Canonical 12.04-lts (including) 12.04-lts (including)
Aptdaemon Ubuntu devel *
Aptdaemon Ubuntu natty *
Aptdaemon Ubuntu oneiric *

Potential Mitigations

References