CVE Vulnerabilities

CVE-2020-15709

Published: Sep 05, 2020 | Modified: Sep 16, 2020
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Versions of add-apt-repository before 0.98.9.2, 0.96.24.32.14, 0.96.20.10, and 0.92.37.8ubuntu0.1~esm1, printed a PPA (personal package archive) description to the terminal as-is, which allowed PPA owners to provide ANSI terminal escapes to modify terminal contents in unexpected ways.

Affected Software

Name Vendor Start Version End Version
Add-apt-repository Canonical 0.92.37.0 (including) 0.92.37.8ubuntu0.1~esm1 (excluding)
Add-apt-repository Canonical 0.96.20.0 (including) 0.96.20.10 (excluding)
Add-apt-repository Canonical 0.96.24.32.0 (including) 0.96.24.32.14 (excluding)
Add-apt-repository Canonical 0.98.9.0 (including) 0.98.9.2 (excluding)
Software-properties Ubuntu bionic *
Software-properties Ubuntu devel *
Software-properties Ubuntu focal *
Software-properties Ubuntu trusty *
Software-properties Ubuntu trusty/esm *
Software-properties Ubuntu xenial *

References