PT-2012-2977 · Canonical · Apt
Published
2012-12-26
·
Updated
2020-01-08
·
CVE-2012-0961
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apt versions 0.8.16exp5ubuntu13.x through 0.8.16exp5ubuntu13.5
Apt versions 0.8.16exp12ubuntu10.x through 0.8.16exp12ubuntu10.6
Apt versions 0.9.7.5ubuntu5.x through 0.9.7.5ubuntu5.1
Description
The issue allows local users to obtain sensitive shell information by reading the log file /var/log/apt/term.log due to world-readable permissions.
Recommendations
For Apt versions 0.8.16exp5ubuntu13.x through 0.8.16exp5ubuntu13.5, update to version 0.8.16exp5ubuntu13.6 or later.
For Apt versions 0.8.16exp12ubuntu10.x through 0.8.16exp12ubuntu10.6, update to version 0.8.16exp12ubuntu10.7 or later.
For Apt versions 0.9.7.5ubuntu5.x through 0.9.7.5ubuntu5.1, update to version 0.9.7.5ubuntu5.2 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apt