CVE-2020-15709

MEDIUM

add-apt-repository < 0.92.37.8ubuntu0.1~esm1 - Terminal Content Manipulation via ANSI Escape Sequences

Title source: llm
STIX 2.1

Description

Versions of add-apt-repository before 0.98.9.2, 0.96.24.32.14, 0.96.20.10, and 0.92.37.8ubuntu0.1~esm1, printed a PPA (personal package archive) description to the terminal as-is, which allowed PPA owners to provide ANSI terminal escapes to modify terminal contents in unexpected ways.

References (1)

Core 1

Scores

CVSS v3 5.5
EPSS 0.0012
EPSS Percentile 30.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-20
Status published
Products (1)
canonical/add-apt-repository 0.92.37.0 - 0.92.37.8ubuntu0.1\~esm1
Published Sep 05, 2020
Tracked Since Feb 18, 2026