CVE-2012-5356: Canonical Ubuntu Software Properties
Medium severity, CVSS 5.8. EPSS: 2% chance of exploitation in the next 30 days.
The apt-add-repository tool in Ubuntu Software Properties 0.75.x before 0.75.10.3, 0.80.x before 0.80.9.2, 0.81.x before 0.81.13.5, 0.82.x before 0.82.7.3, and 0.92.x before 0.92.8 does not properly check PPA GPG keys imported from a keyserver, which allows remote attackers to install arbitrary package repository GPG keys via a man-in-the-middle (MITM) attack.
Affected products
- Canonical Ubuntu Software Properties: version 0.75.4 only; version 0.75.5 only; version 0.75.6 only; version 0.75.7 only; version 0.75.8 only; version 0.75.9 only; …
Published 2012-10-10. Last modified 2026-06-16.