CVE-2012-0954: Input Validation
APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install altered packages via a man-in-the-middle (MITM) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3587.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0954?
CVE-2012-0954 is considered a high severity vulnerability as it allows remote attackers to potentially install altered packages through a man-in-the-middle (MITM) attack.
How do I fix CVE-2012-0954?
To fix CVE-2012-0954, upgrade the affected APT version to 0.7.25 or 0.8.16 or later, which addresses the vulnerability.
What versions of APT are affected by CVE-2012-0954?
CVE-2012-0954 affects APT versions 0.7.x before 0.7.25 and 0.8.x before 0.8.16.
What kind of attack is associated with CVE-2012-0954?
CVE-2012-0954 is associated with man-in-the-middle (MITM) attacks that could allow an attacker to intercept and alter package installations.
Does CVE-2012-0954 impact package integrity?
Yes, CVE-2012-0954 compromises package integrity by potentially allowing the installation of tampered packages.