CVE-2020-15709

EUVD-2020-7695
Versions of add-apt-repository before 0.98.9.2, 0.96.24.32.14, 0.96.20.10, and 0.92.37.8ubuntu0.1~esm1, printed a PPA (personal package archive) description to the terminal as-is, which allowed PPA owners to provide ANSI terminal escapes to modify terminal contents in unexpected ways.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 11%
Affected Products (NVD)
VendorProductVersion
canonicaladd-apt-repository
0.92.37.0 ≤
canonicaladd-apt-repository
0.96.20.0 ≤
𝑥
< 0.96.20.10
canonicaladd-apt-repository
0.96.24.32.0 ≤
𝑥
< 0.96.24.32.14
canonicaladd-apt-repository
0.98.9.0 ≤
𝑥
< 0.98.9.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
software-properties
bookworm
unimportant
bullseye
unimportant
sid
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
software-properties
bionic
Fixed 0.96.24.32.14
released
focal
Fixed 0.98.9.2
released
trusty
Fixed 0.92.37.8ubuntu0.1~esm1
released
xenial
Fixed 0.96.20.10
released