CVE-2012-0944
04.06.2012, 20:55
Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is not simulated, which allows remote attackers to install arbitrary packages via a man-in-the-middle attack.Enginsight
Vendor | Product | Version |
---|---|---|
sebastian_heinlein | aptdaemon | 𝑥 ≤ 0.42 |
sebastian_heinlein | aptdaemon | 0.20 |
sebastian_heinlein | aptdaemon | 0.30 |
sebastian_heinlein | aptdaemon | 0.31 |
sebastian_heinlein | aptdaemon | 0.32 |
sebastian_heinlein | aptdaemon | 0.33 |
sebastian_heinlein | aptdaemon | 0.34 |
sebastian_heinlein | aptdaemon | 0.40 |
sebastian_heinlein | aptdaemon | 0.41 |
canonical | ubuntu_linux | 11.04 |
canonical | ubuntu_linux | 11.10 |
canonical | ubuntu_linux | 12.04:lts |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References