Security Flaw in APT Package Manager by Ubuntu Affects Key Management
CVE-2012-3587

Currently unrated

Key Information:

Vendor

Debian

Vendor
CVE Published:
19 June 2012

What is CVE-2012-3587?

A security flaw in APT versions prior to 0.7.25 and 0.8.16 allows for exploitation through the improper handling of GnuPG argument order. This vulnerability occurs when using the apt-key net-update command to import keyrings, failing to verify GPG subkeys. As a result, attackers can execute man-in-the-middle (MITM) attacks to exploit this weakness, potentially enabling them to install malicious packages disguised as legitimate software.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.