CVE-2012-0955

Publication date 2 December 2020

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

7.4 · High

Score breakdown

Description

software-properties was vulnerable to a person-in-the-middle attack due to incorrect TLS certificate validation in softwareproperties/ppa.py. software-properties didn't check TLS certificates under python2 and only checked certificates under python3 if a valid certificate bundle was provided. Fixed in software-properties version 0.92.

Read the notes from the security team

Status

Package Ubuntu Release Status
software-properties 13.04 raring
Not affected
12.10 quantal
Not affected
12.04 LTS precise
Not affected
10.04 LTS lucid Ignored end of life

Notes


mdeslaur

introduced in 0.84

Severity score breakdown

CVSS version: CVSS v3.0

Base score 7.4 · High

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N


Access our resources on patching vulnerabilities