CVE-2012-0955
Publication date 2 December 2020
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
software-properties was vulnerable to a person-in-the-middle attack due to incorrect TLS certificate validation in softwareproperties/ppa.py. software-properties didn't check TLS certificates under python2 and only checked certificates under python3 if a valid certificate bundle was provided. Fixed in software-properties version 0.92.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| software-properties | ||
Notes
Severity score breakdown
CVSS version: CVSS v3.0
Base score
7.4 · High
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N