CVE-2012-0954 describes a vulnerability in APT versions 0.7.x before 0.7.25 and 0.8.x before 0.8.16, specifically when using the apt-key net-update command to import keyrings. This flaw, an incomplete fix for CVE-2012-3587, stems from APT's reliance on GnuPG argument order and its failure to check GPG subkeys. This could enable a remote attacker to install altered packages through a man-in-the-middle (MITM) attack. The vulnerability has a CVSS score of 2.6, indicating low severity with a network attack vector and high access complexity, potentially leading to partial integrity compromise (installation of altered packages) but no confidentiality or availability impact. Its EPSS score is very low, and its FAUCET Risk Score is 6/100. There is no evidence of active exploitation, nor is exploit code available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community attention, with no social media discussion or media coverage reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.7.0CPE matchmatch criteria | cpe:2.3:a:debian:advanced_package_tool:0.7.0:*:*:*:*:*:*:* | ||
0.7.1CPE matchmatch criteria | cpe:2.3:a:debian:advanced_package_tool:0.7.1:*:*:*:*:*:*:* | ||
0.7.2CPE matchmatch criteria | cpe:2.3:a:debian:advanced_package_tool:0.7.2:*:*:*:*:*:*:* | ||
0.7.2-0.1CPE matchmatch criteria | cpe:2.3:a:debian:advanced_package_tool:0.7.2-0.1:*:*:*:*:*:*:* | ||
0.7.10CPE matchmatch criteria | cpe:2.3:a:debian:advanced_package_tool:0.7.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.