AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2012-5356

MEDIUM · CVSS 5.8 EPSS 1.97%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2012-10-10 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.8. It affects Ubuntu. It may be remotely exploitable.

CVE
CVE-2012-5356
Severity
MEDIUM
CVSS
5.8
EPSS
1.97%
Ubuntu

Original NVD Description

The apt-add-repository tool in Ubuntu Software Properties 0.75.x before 0.75.10.3, 0.80.x before 0.80.9.2, 0.81.x before 0.81.13.5, 0.82.x before 0.82.7.3, and 0.92.x before 0.92.8 does not properly check PPA GPG keys imported from a keyserver, which allows remote attackers to install arbitrary package repository GPG keys via a man-in-the-middle (MITM) attack.