CVE-2012-0944: Canonical Ubuntu Linux

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is not simulated, which allows remote attackers to install arbitrary packages via a man-in-the-middle attack.

Affected products

  • Canonical Ubuntu Linux: version 11.04 only; version 11.10 only; version 12.04 only
  • Sebastian Heinlein Aptdaemon: up to and including 0.42; version 0.20 only; version 0.30 only; version 0.31 only; version 0.32 only; version 0.33 only; …

Published 2012-06-04. Last modified 2026-06-16.