2.6

CVE-2012-0954

APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install altered packages via a man-in-the-middle (MITM) attack.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3587.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DebianAdvanced Package Tool Version0.7.0
DebianAdvanced Package Tool Version0.7.1
DebianAdvanced Package Tool Version0.7.2
DebianAdvanced Package Tool Version0.7.2-0.1
DebianAdvanced Package Tool Version0.7.10
DebianAdvanced Package Tool Version0.7.11
DebianAdvanced Package Tool Version0.7.12
DebianAdvanced Package Tool Version0.7.13
DebianAdvanced Package Tool Version0.7.14
DebianAdvanced Package Tool Version0.7.15
DebianAdvanced Package Tool Version0.7.15 Updateexp1
DebianAdvanced Package Tool Version0.7.15 Updateexp2
DebianAdvanced Package Tool Version0.7.15 Updateexp3
DebianAdvanced Package Tool Version0.7.16
DebianAdvanced Package Tool Version0.7.17
DebianAdvanced Package Tool Version0.7.17 Updateexp1
DebianAdvanced Package Tool Version0.7.17 Updateexp2
DebianAdvanced Package Tool Version0.7.17 Updateexp3
DebianAdvanced Package Tool Version0.7.17 Updateexp4
DebianAdvanced Package Tool Version0.7.18
DebianAdvanced Package Tool Version0.7.19
DebianAdvanced Package Tool Version0.7.20
DebianAdvanced Package Tool Version0.7.20.1
DebianAdvanced Package Tool Version0.7.20.2
DebianAdvanced Package Tool Version0.7.21
DebianAdvanced Package Tool Version0.7.22
DebianAdvanced Package Tool Version0.7.22.1
DebianAdvanced Package Tool Version0.7.22.2
DebianAdvanced Package Tool Version0.7.23
DebianAdvanced Package Tool Version0.7.23.1
DebianAdvanced Package Tool Version0.7.24
DebianAdvanced Package Tool Version0.8.0
DebianAdvanced Package Tool Version0.8.0 Updatepre1
DebianAdvanced Package Tool Version0.8.0 Updatepre2
DebianAdvanced Package Tool Version0.8.1
DebianAdvanced Package Tool Version0.8.10
DebianAdvanced Package Tool Version0.8.10.1
DebianAdvanced Package Tool Version0.8.10.2
DebianAdvanced Package Tool Version0.8.10.3
DebianAdvanced Package Tool Version0.8.11
DebianAdvanced Package Tool Version0.8.11.1
DebianAdvanced Package Tool Version0.8.11.2
DebianAdvanced Package Tool Version0.8.11.3
DebianAdvanced Package Tool Version0.8.11.4
DebianAdvanced Package Tool Version0.8.11.5
DebianAdvanced Package Tool Version0.8.12
DebianAdvanced Package Tool Version0.8.13
DebianAdvanced Package Tool Version0.8.13.1
DebianAdvanced Package Tool Version0.8.13.2
DebianAdvanced Package Tool Version0.8.14
DebianAdvanced Package Tool Version0.8.14.1
DebianAdvanced Package Tool Version0.8.15
DebianAdvanced Package Tool Version0.8.15 Updateexp1
DebianAdvanced Package Tool Version0.8.15 Updateexp2
DebianAdvanced Package Tool Version0.8.15 Updateexp3
DebianAdvanced Package Tool Version0.8.15.1
DebianAdvanced Package Tool Version0.8.15.6
DebianAdvanced Package Tool Version0.8.15.7
DebianAdvanced Package Tool Version0.8.15.8
DebianAdvanced Package Tool Version0.8.15.9
DebianAdvanced Package Tool Version0.8.15.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.558
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.