CVE-2012-3587

low
Published 2012-06-19 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
2.6

Description

APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install Trojan horse packages via a man-in-the-middle (MITM) attack.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 0.7.25
sid Fixed 0.7.25
forky Fixed 0.7.25
bullseye Fixed 0.7.25
bookworm Fixed 0.7.25

Application impact

VendorProductVersionsFixed
debian debianadvanced_package_tool0.7.0
debian debianadvanced_package_tool0.7.1
debian debianadvanced_package_tool0.7.2
debian debianadvanced_package_tool0.7.2-0.1
debian debianadvanced_package_tool0.7.10
debian debianadvanced_package_tool0.7.11
debian debianadvanced_package_tool0.7.12
debian debianadvanced_package_tool0.7.13
debian debianadvanced_package_tool0.7.14
debian debianadvanced_package_tool0.7.15
debian debianadvanced_package_tool0.7.16
debian debianadvanced_package_tool0.7.17
debian debianadvanced_package_tool0.7.18
debian debianadvanced_package_tool0.7.19
debian debianadvanced_package_tool0.7.20
debian debianadvanced_package_tool0.7.20.1
debian debianadvanced_package_tool0.7.20.2
debian debianadvanced_package_tool0.7.21
debian debianadvanced_package_tool0.7.22
debian debianadvanced_package_tool0.7.22.1
debian debianadvanced_package_tool0.7.22.2
debian debianadvanced_package_tool0.7.23
debian debianadvanced_package_tool0.7.23.1
debian debianadvanced_package_tool0.7.24
debian debianadvanced_package_tool0.8.0
debian debianadvanced_package_tool0.8.1
debian debianadvanced_package_tool0.8.10
debian debianadvanced_package_tool0.8.10.1
debian debianadvanced_package_tool0.8.10.2
debian debianadvanced_package_tool0.8.10.3
debian debianadvanced_package_tool0.8.11
debian debianadvanced_package_tool0.8.11.1
debian debianadvanced_package_tool0.8.11.2
debian debianadvanced_package_tool0.8.11.3
debian debianadvanced_package_tool0.8.11.4
debian debianadvanced_package_tool0.8.11.5
debian debianadvanced_package_tool0.8.12
debian debianadvanced_package_tool0.8.13
debian debianadvanced_package_tool0.8.13.1
debian debianadvanced_package_tool0.8.13.2
debian debianadvanced_package_tool0.8.14
debian debianadvanced_package_tool0.8.14.1
debian debianadvanced_package_tool0.8.15
debian debianadvanced_package_tool0.8.15.1
debian debianadvanced_package_tool0.8.15.6
debian debianadvanced_package_tool0.8.15.7
debian debianadvanced_package_tool0.8.15.8
debian debianadvanced_package_tool0.8.15.9
debian debianadvanced_package_tool0.8.15.10

References

CWEs

CWE-20

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.