CVE-2020-15709: Canonical Add-Apt-Repository
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Versions of add-apt-repository before 0.98.9.2, 0.96.24.32.14, 0.96.20.10, and 0.92.37.8ubuntu0.1~esm1, printed a PPA (personal package archive) description to the terminal as-is, which allowed PPA owners to provide ANSI terminal escapes to modify terminal contents in unexpected ways.
Affected products
- Canonical Add-Apt-Repository: from 0.92.37.0, before 0.92.37.8ubuntu0.1\~esm1 (fixed in 0.92.37.8ubuntu0.1\~esm1); from 0.96.20.0, before 0.96.20.10 (fixed in 0.96.20.10); from 0.96.24.32.0, before 0.96.24.32.14 (fixed in 0.96.24.32.14); from 0.98.9.0, before 0.98.9.2 (fixed in 0.98.9.2)
Published 2020-09-05. Last modified 2026-06-17.