CVE-2012-0961

low
Published 2012-12-26 · Modified 2026-04-29
CVSS v3
CVSS v2
2.1
VIR risk
2.1

Description

Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/apt/term.log, which allows local users to obtain sensitive shell information by reading the log file.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security@ubuntu.com — http://www.ubuntu.com/usn/USN-1662-1

vendor Authored 2026-05-27

Vendor advisory: security@ubuntu.com — http://secunia.com/advisories/51568

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-0961

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0.9.7.7
debian debianbullseyefixed0.9.7.7
debian debianforkyfixed0.9.7.7
debian debiansidfixed0.9.7.7
debian debiantrixiefixed0.9.7.7

Application impact

VendorProductVersionsFixed
debianadvanced_package_tool0.8.16
debianapt0.9.7

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.