CVE-2012-3587: Input Validation
APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install Trojan horse packages via a man-in-the-middle (MITM) attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3587?
CVE-2012-3587 is classified as a high-severity vulnerability due to its potential for remote exploitation via man-in-the-middle attacks.
How do I fix CVE-2012-3587?
To fix CVE-2012-3587, upgrade to Advanced Package Tool versions 0.7.25, 0.8.16, or later.
What systems are affected by CVE-2012-3587?
CVE-2012-3587 affects versions 0.7.x prior to 0.7.25 and 0.8.x prior to 0.8.16 of the Advanced Package Tool.
How does CVE-2012-3587 work?
CVE-2012-3587 works by exploiting the reliance on GnuPG argument order and lack of GPG subkey verification to allow attackers to install unverified packages.
Is there a workaround for CVE-2012-3587?
There is no officially recommended workaround for CVE-2012-3587; the best course of action is to apply the available updates.