5.5
CVSSv3

CVE-2020-15709

Published: 05/09/2020 Updated: 16/09/2020
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Versions of add-apt-repository prior to 0.98.9.2, 0.96.24.32.14, 0.96.20.10, and 0.92.37.8ubuntu0.1~esm1, printed a PPA (personal package archive) description to the terminal as-is, which allowed PPA owners to provide ANSI terminal escapes to modify terminal contents in unexpected ways.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canonical add-apt-repository

Vendor Advisories

Debian Bug report logs - #968850 software-properties: CVE-2020-15709 Package: src:software-properties; Maintainer for src:software-properties is Julian Andres Klode <jak@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 22 Aug 2020 11:15:03 UTC Severity: important Tags: security, upstream ...