Search CVE reports


Toggle filters

1 – 5 of 5 results


CVE-2012-0955

Medium priority
Ignored

software-properties was vulnerable to a person-in-the-middle attack due to incorrect TLS certificate validation in softwareproperties/ppa.py. software-properties didn't check TLS certificates under python2 and only checked...

1 affected package

software-properties

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
software-properties
Show less packages

CVE-2020-15709

Medium priority
Fixed

Versions of add-apt-repository before 0.98.9.2, 0.96.24.32.14, 0.96.20.10, and 0.92.37.8ubuntu0.1~esm1, printed a PPA (personal package archive) description to the terminal as-is, which allowed PPA owners to provide ANSI terminal...

1 affected package

software-properties

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
software-properties Fixed Fixed Fixed
Show less packages

CVE-2013-1061

Medium priority

Some fixes available 3 of 4

dbus/SoftwarePropertiesDBus.py in Software Properties 0.92.17 before 0.92.17.3, 0.92.9 before 0.92.9.3, and 0.82.7 before 0.82.7.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to...

1 affected package

software-properties

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
software-properties
Show less packages

CVE-2012-5356

Medium priority

Some fixes available 4 of 5

The apt-add-repository tool in Ubuntu Software Properties 0.75.x before 0.75.10.3, 0.80.x before 0.80.9.2, 0.81.x before 0.81.13.5, 0.82.x before 0.82.7.3, and 0.92.x before 0.92.8 does not properly check PPA GPG keys imported...

1 affected package

software-properties

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
software-properties
Show less packages

CVE-2011-4407

Medium priority

Some fixes available 4 of 5

ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.

1 affected package

software-properties

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
software-properties
Show less packages