CVE-2020-15709

Versions of add-apt-repository before 0.98.9.2, 0.96.24.32.14, 0.96.20.10, and 0.92.37.8ubuntu0.1~esm1, printed a PPA (personal package archive) description to the terminal as-is, which allowed PPA owners to provide ANSI terminal escapes to modify terminal contents in unexpected ways.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
canonicalCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
VendorProductVersion
canonicaladd-apt-repository
0.92.37.0 ≤
canonicaladd-apt-repository
0.96.20.0 ≤
𝑥
< 0.96.20.10
canonicaladd-apt-repository
0.96.24.32.0 ≤
𝑥
< 0.96.24.32.14
canonicaladd-apt-repository
0.98.9.0 ≤
𝑥
< 0.98.9.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
software-properties
bullseye
unimportant
bookworm
unimportant
sid
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
software-properties
focal
Fixed 0.98.9.2
released
bionic
Fixed 0.96.24.32.14
released
xenial
Fixed 0.96.20.10
released
trusty
Fixed 0.92.37.8ubuntu0.1~esm1
released