CVE-2011-4407

ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
canonicalCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
VendorProductVersion
canonicalsoftware-properties
𝑥
≤ 0.81.13.1
canonicalubuntu_linux
10.04
canonicalubuntu_linux
10.10
canonicalubuntu_linux
11.04
canonicalubuntu_linux
11.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
software-properties
bullseye
0.96.20.2-2.1
fixed
squeeze
not-affected
lenny
not-affected
bookworm
0.99.30-4.1~deb12u1
fixed
sid
0.99.30-4.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
software-properties
oneiric
Fixed 0.81.13.3
released
natty
Fixed 0.80.9.1
released
maverick
Fixed 0.76.7.1
released
lucid
Fixed 0.75.10.2
released
hardy
ignored