CVE-2012-0961: Infoleak
Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/apt/term.log, which allows local users to obtain sensitive shell information by reading the log file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0961?
CVE-2012-0961 is considered a medium severity vulnerability due to local information disclosure risks.
How do I fix CVE-2012-0961?
To fix CVE-2012-0961, update the APT package to the latest version that addresses the permissions issue.
What type of vulnerability is CVE-2012-0961?
CVE-2012-0961 is an information disclosure vulnerability caused by world-readable permissions on sensitive log files.
Which versions of APT are affected by CVE-2012-0961?
APT versions 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2 are affected by CVE-2012-0961.
Who can exploit the vulnerabilities in CVE-2012-0961?
CVE-2012-0961 can be exploited by local users who have access to the system where the vulnerable versions of APT are installed.