CVE-2012-0944
Status: ModifiedMedium (4.3)—
Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is not simulated, which allows remote attackers to install arbitrary packages via a man-in-the-middle attack.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
- Base score: 4.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.21%
- Percentile among all scored CVEs: 67
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
CWEs
- CWE-287
References
- http://secunia.com/advisories/48688
- http://ubuntu.com/usn/usn-1414-1
- http://www.osvdb.org/80887
- http://www.securityfocus.com/bid/52855
- https://bugs.launchpad.net/ubuntu/%2Bsource/aptdaemon/%2Bbug/959131
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74553
- http://secunia.com/advisories/48688
- http://ubuntu.com/usn/usn-1414-1
- http://www.osvdb.org/80887
- http://www.securityfocus.com/bid/52855
- https://bugs.launchpad.net/ubuntu/%2Bsource/aptdaemon/%2Bbug/959131
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74553
Raw JSON (NVD)
Show
{
"id": "CVE-2012-0944",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "security@ubuntu.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-06-04T20:55:02.667",
"references": [
{
"url": "http://secunia.com/advisories/48688",
"tags": [
"Vendor Advisory"
],
"source": "security@ubuntu.com"
},
{
"url": "http://ubuntu.com/usn/usn-1414-1",
"source": "security@ubuntu.com"
},
{
"url": "http://www.osvdb.org/80887",
"source": "security@ubuntu.com"
},
{
"url": "http://www.securityfocus.com/bid/52855",
"source": "security@ubuntu.com"
},
{
"url": "https://bugs.launchpad.net/ubuntu/%2Bsource/aptdaemon/%2Bbug/959131",
"source": "security@ubuntu.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/74553",
"source": "security@ubuntu.com"
},
{
"url": "http://secunia.com/advisories/48688",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://ubuntu.com/usn/usn-1414-1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/80887",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/52855",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugs.launchpad.net/ubuntu/%2Bsource/aptdaemon/%2Bbug/959131",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/74553",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is not simulated, which allows remote attackers to install arbitrary packages via a man-in-the-middle attack."
},
{
"lang": "es",
"value": "v0.43 y anteriores en Ubuntu 11.04, v11.10, y v12.04 LTS no autentica los paquetes cuando la transacción no es simulada, lo que permite a atacantes remotos a instalar paquetes a través de ataques \"man-in-the-middle\"."
}
],
"lastModified": "2026-06-16T23:38:33.247",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sebastian_heinlein:aptdaemon:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DDA070A6-E888-45FA-A51C-5AAF94575186",
"versionEndIncluding": "0.42"
},
{
"criteria": "cpe:2.3:a:sebastian_heinlein:aptdaemon:0.20:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3DC245C4-29B1-4932-B2AC-DD839AE73F80"
},
{
"criteria": "cpe:2.3:a:sebastian_heinlein:aptdaemon:0.30:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF35FE2C-069A-4655-B89D-09E1D8A6AAA7"
},
{
"criteria": "cpe:2.3:a:sebastian_heinlein:aptdaemon:0.31:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C17B1B89-B1F8-4033-8B55-4103D3B25055"
},
{
"criteria": "cpe:2.3:a:sebastian_heinlein:aptdaemon:0.32:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12ADB378-57FF-4119-B366-70CD9404F021"
},
{
"criteria": "cpe:2.3:a:sebastian_heinlein:aptdaemon:0.33:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "274F5887-CA53-4F3E-B4A1-4E47B9630452"
},
{
"criteria": "cpe:2.3:a:sebastian_heinlein:aptdaemon:0.34:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5DB11186-CA4D-48F6-8B55-91D3D7B8603A"
},
{
"criteria": "cpe:2.3:a:sebastian_heinlein:aptdaemon:0.40:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BFBCA267-B4A8-4D72-AEB5-90E1CD811C80"
},
{
"criteria": "cpe:2.3:a:sebastian_heinlein:aptdaemon:0.41:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4C2B6B38-1636-4B5F-9D08-65F8F3C46D5B"
},
{
"criteria": "cpe:2.3:o:canonical:ubuntu_linux:11.04:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EF49D26F-142E-468B-87C1-BABEA445255C"
},
{
"criteria": "cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E4174F4F-149E-41A6-BBCC-D01114C05F38"
},
{
"criteria": "cpe:2.3:o:canonical:ubuntu_linux:12.04:lts:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B7634053-30B3-4577-9B13-1782DD5B9762"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@ubuntu.com"
}