CVE-2012-0950

Publication date 4 June 2012

Last updated 24 July 2024


Ubuntu priority

The Apport hook (DistUpgradeApport.py) in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uploads the /var/log/dist-upgrade directory when reporting bugs to Launchpad, which allows remote attackers to read repository credentials by viewing a public bug report. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0949.

Status

Package Ubuntu Release Status
update-manager 12.04 LTS precise
Fixed 1:0.156.14.5
11.10 oneiric
Fixed 1:0.152.25.12
11.04 natty
Fixed 1:0.150.5.4
10.04 LTS lucid
Not affected
8.04 LTS hardy
Not affected

References

Related Ubuntu Security Notices (USN)

    • USN-1443-2
    • Update Manager vulnerability
    • 4 June 2012

Other references