CVE-2012-0962

aptdaemon 0.43 - Man-in-the-Middle GPG Key Spoofing via Short Key IDs

Title source: llm
STIX 2.1

Description

Aptdaemon 0.43 in Ubuntu 11.10 and 12.04 LTS uses short IDs when importing PPA GPG keys from a keyserver, which allows remote attackers to install arbitrary package repository GPG keys via a man-in-the-middle (MITM) attack.

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51627
Patch vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1666-1
Patch vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1027891
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/56959

Scores

EPSS 0.0180
EPSS Percentile 76.1%

Details

Status published
Products (3)
canonical/ubuntu_linux 11.10
canonical/ubuntu_linux 12.04
sebastian_heinlein/aptdaemon 0.43
Published Dec 26, 2012
Tracked Since Feb 18, 2026