CVE-2012-0214

Source
https://nvd.nist.gov/vuln/detail/CVE-2012-0214
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2012-0214.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2012-0214
Published
2014-04-15T23:55:08Z
Modified
2024-11-21T01:34:35Z
Summary
[none]
Details

The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before 0.8.16~exp13, when updating from repositories that use InRelease files, allows man-in-the-middle attackers to install arbitrary packages by preventing a user from downloading the new InRelease file, which leaves the original InRelease file active and makes it more difficult to detect that the Packages file is modified and unsigned.

References

Affected packages

Debian:11 / apt

Package

Name
apt
Purl
pkg:deb/debian/apt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.8.15.10

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / apt

Package

Name
apt
Purl
pkg:deb/debian/apt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.8.15.10

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / apt

Package

Name
apt
Purl
pkg:deb/debian/apt?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.8.15.10

Ecosystem specific

{
    "urgency": "not yet assigned"
}