CVE-2012-0948: Low severity Gnome Update-manager-core vulnerability
Published Jun 7, 2012
·Updated
DistUpgrade/DistUpgradeMain.py in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uses weak permissions for (1) apt-clonesystemstate.tar.gz and (2) systemstate.tar.gz, which allows local users to obtain repository credentials.
Affected Software
6 affected components
Gnome Update-manager-core=0.150.5.2
Gnome Update-manager-core=0.152.25.10
Gnome Update-manager-core=0.156.14.3
Canonical Ubuntu Linux=11.04
Canonical Ubuntu Linux=11.10
Canonical Ubuntu Linux=12.04
Event History
Jun 7, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0948?
CVE-2012-0948 has a medium severity level due to the potential exposure of repository credentials to local users.
2
How do I fix CVE-2012-0948?
To fix CVE-2012-0948, apply the latest updates to the Update Manager or modify permissions on the affected files accordingly.
3
Which Ubuntu versions are affected by CVE-2012-0948?
CVE-2012-0948 affects Ubuntu versions 11.04, 11.10, and 12.04 LTS.
4
What type of vulnerability is CVE-2012-0948?
CVE-2012-0948 is a local privilege escalation vulnerability.
5
Can local users exploit CVE-2012-0948?
Yes, local users can exploit CVE-2012-0948 to obtain repository credentials through weak file permissions.