Vulnerability Details CVE-2012-0954
APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install altered packages via a man-in-the-middle (MITM) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3587.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.8%
CVSS Severity
CVSS v2 Score 2.6
Products affected by CVE-2012-0954
-
cpe:2.3:a:debian:advanced_package_tool:0.7.0
-
cpe:2.3:a:debian:advanced_package_tool:0.7.1
-
cpe:2.3:a:debian:advanced_package_tool:0.7.10
-
cpe:2.3:a:debian:advanced_package_tool:0.7.11
-
cpe:2.3:a:debian:advanced_package_tool:0.7.12
-
cpe:2.3:a:debian:advanced_package_tool:0.7.13
-
cpe:2.3:a:debian:advanced_package_tool:0.7.14
-
cpe:2.3:a:debian:advanced_package_tool:0.7.15
-
cpe:2.3:a:debian:advanced_package_tool:0.7.16
-
cpe:2.3:a:debian:advanced_package_tool:0.7.17
-
cpe:2.3:a:debian:advanced_package_tool:0.7.18
-
cpe:2.3:a:debian:advanced_package_tool:0.7.19
-
cpe:2.3:a:debian:advanced_package_tool:0.7.2
-
cpe:2.3:a:debian:advanced_package_tool:0.7.2-0.1
-
cpe:2.3:a:debian:advanced_package_tool:0.7.20
-
cpe:2.3:a:debian:advanced_package_tool:0.7.20.1
-
cpe:2.3:a:debian:advanced_package_tool:0.7.20.2
-
cpe:2.3:a:debian:advanced_package_tool:0.7.21
-
cpe:2.3:a:debian:advanced_package_tool:0.7.22
-
cpe:2.3:a:debian:advanced_package_tool:0.7.22.1
-
cpe:2.3:a:debian:advanced_package_tool:0.7.22.2
-
cpe:2.3:a:debian:advanced_package_tool:0.7.23
-
cpe:2.3:a:debian:advanced_package_tool:0.7.23.1
-
cpe:2.3:a:debian:advanced_package_tool:0.7.24
-
cpe:2.3:a:debian:advanced_package_tool:0.8.0
-
cpe:2.3:a:debian:advanced_package_tool:0.8.1
-
cpe:2.3:a:debian:advanced_package_tool:0.8.10
-
cpe:2.3:a:debian:advanced_package_tool:0.8.10.1
-
cpe:2.3:a:debian:advanced_package_tool:0.8.10.2
-
cpe:2.3:a:debian:advanced_package_tool:0.8.10.3
-
cpe:2.3:a:debian:advanced_package_tool:0.8.11
-
cpe:2.3:a:debian:advanced_package_tool:0.8.11.1
-
cpe:2.3:a:debian:advanced_package_tool:0.8.11.2
-
cpe:2.3:a:debian:advanced_package_tool:0.8.11.3
-
cpe:2.3:a:debian:advanced_package_tool:0.8.11.4
-
cpe:2.3:a:debian:advanced_package_tool:0.8.11.5
-
cpe:2.3:a:debian:advanced_package_tool:0.8.12
-
cpe:2.3:a:debian:advanced_package_tool:0.8.13
-
cpe:2.3:a:debian:advanced_package_tool:0.8.13.1
-
cpe:2.3:a:debian:advanced_package_tool:0.8.13.2
-
cpe:2.3:a:debian:advanced_package_tool:0.8.14
-
cpe:2.3:a:debian:advanced_package_tool:0.8.14.1
-
cpe:2.3:a:debian:advanced_package_tool:0.8.15
-
cpe:2.3:a:debian:advanced_package_tool:0.8.15.1
-
cpe:2.3:a:debian:advanced_package_tool:0.8.15.10
-
cpe:2.3:a:debian:advanced_package_tool:0.8.15.6
-
cpe:2.3:a:debian:advanced_package_tool:0.8.15.7
-
cpe:2.3:a:debian:advanced_package_tool:0.8.15.8
-
cpe:2.3:a:debian:advanced_package_tool:0.8.15.9