Vulnerability Description
Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/apt/term.log, which allows local users to obtain sensitive shell information by reading the log file.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Advanced Package Tool | 0.8.16 |
| Debian | Apt | 0.9.7 |
Related Weaknesses (CWE)
References
- http://osvdb.org/88380
- http://secunia.com/advisories/51568Vendor Advisory
- http://www.securityfocus.com/bid/56917
- http://www.ubuntu.com/usn/USN-1662-1PatchVendor Advisory
- http://osvdb.org/88380
- http://secunia.com/advisories/51568Vendor Advisory
- http://www.securityfocus.com/bid/56917
- http://www.ubuntu.com/usn/USN-1662-1PatchVendor Advisory
FAQ
What is CVE-2012-0961?
CVE-2012-0961 is a vulnerability with a CVSS score of 2.1 (LOW). Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permi...
How severe is CVE-2012-0961?
CVE-2012-0961 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-0961?
Check the references section above for vendor advisories and patch information. Affected products include: Debian Advanced Package Tool, Debian Apt.