CVE-2012-0962
Publication date 17 December 2012
Last updated 24 July 2024
Ubuntu priority
Description
Aptdaemon 0.43 in Ubuntu 11.10 and 12.04 LTS uses short IDs when importing PPA GPG keys from a keyserver, which allows remote attackers to install arbitrary package repository GPG keys via a man-in-the-middle (MITM) attack.
Notes
mdeslaur
quantal and higher use add_key_from_keyserver() in python-apt which does use long gpg keyids lucid doesn't use apt-key
References
Related Ubuntu Security Notices (USN)
- USN-1666-1
- Aptdaemon vulnerability
- 17 December 2012