« Volver al listado

CVE-2020-15709

Estado: ModificadaMedia (5.5)—

Versions of add-apt-repository before 0.98.9.2, 0.96.24.32.14, 0.96.20.10, and 0.92.37.8ubuntu0.1~esm1, printed a PPA (personal package archive) description to the terminal as-is, which allowed PPA owners to provide ANSI terminal escapes to modify terminal contents in unexpected ways.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-15709",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@ubuntu.com",
      "affectedData": [
        {
          "vendor": "Canonical",
          "product": "add-apt-repository",
          "versions": [
            {
              "status": "affected",
              "version": "0.98.9.*",
              "lessThan": "0.98.9.2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0.96.24.32.*",
              "lessThan": "0.96.24.32.14",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0.96.20.*",
              "lessThan": "0.96.20.10",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0.92.37.*",
              "lessThan": "0.92.37.8ubuntu0.1~esm1",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-09-05T04:15:13.743",
  "references": [
    {
      "url": "https://git.launchpad.net/software-properties/commit/add-apt-repository?id=97e2fe7d181e8711e0f5253d3b8db40426c17f1e",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://git.launchpad.net/software-properties/commit/add-apt-repository?id=97e2fe7d181e8711e0f5253d3b8db40426c17f1e",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@ubuntu.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Versions of add-apt-repository before 0.98.9.2, 0.96.24.32.14, 0.96.20.10, and 0.92.37.8ubuntu0.1~esm1, printed a PPA (personal package archive) description to the terminal as-is, which allowed PPA owners to provide ANSI terminal escapes to modify terminal contents in unexpected ways."
    },
    {
      "lang": "es",
      "value": "Las versiones de add-apt-repository anteriores a 0.98.9.2, 0.96.24.32.14, 0.96.20.10 y 0.92.37.8ubuntu0.1~esm1, imprimieron una descripción PPA (personal package archive) en el terminal as-is, lo que permitió a los propietarios de PPA proporcionar escapes del terminal ANSI para modificar el contenido del terminal de formas no previstas"
    }
  ],
  "lastModified": "2026-06-17T02:57:06.030",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:canonical:add-apt-repository:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A41B5913-0F89-40CB-AE3C-C955965675F3",
              "versionEndExcluding": "0.92.37.8ubuntu0.1\\~esm1",
              "versionStartIncluding": "0.92.37.0"
            },
            {
              "criteria": "cpe:2.3:a:canonical:add-apt-repository:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09EB5C38-87CE-4863-A281-968CCFB44F5F",
              "versionEndExcluding": "0.96.20.10",
              "versionStartIncluding": "0.96.20.0"
            },
            {
              "criteria": "cpe:2.3:a:canonical:add-apt-repository:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AD750E43-D532-496D-B63A-A664870A60CA",
              "versionEndExcluding": "0.96.24.32.14",
              "versionStartIncluding": "0.96.24.32.0"
            },
            {
              "criteria": "cpe:2.3:a:canonical:add-apt-repository:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D631968-A108-4DE4-B4FD-2025AF9F91A0",
              "versionEndExcluding": "0.98.9.2",
              "versionStartIncluding": "0.98.9.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@ubuntu.com"
}