← Vulnerability feed

Vulnerability record · CVE-2012-3587 · published 19 June 2012

CVE-2012-3587: Debian advanced package tool improper input validation vulnerability

Debian · Advanced Package Tool

APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install Trojan horse packages via a man-in-the-middle (MITM) attack.

2.6 CVSS 2.0 Low EPSS 1.7% · top 23.7% CWE-20 · Improper input validation
2.6CVSS 2.0 base score
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install Trojan horse packages via a man-in-the-middle (MITM) attack.

AV:N/AC:H/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-3587 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-1358Debian advanced package tool vulnerabilityapt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has be…EPSS 4.5%10.0CVE-2009-1300Debian advanced package tool improper input validation vulnerabilityapt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones fo…EPSS 1.9%8.1CVE-2019-3462Debian advanced package tool vulnerabilityIncorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM att…EPSS 15%7.5CVE-2014-0487Debian advanced package tool vulnerabilityAPT before 1.0.9 does not verify downloaded files if they have been modified as indicated using the If-Modified-Since header, which has unspecified i…EPSS 1.9%7.5CVE-2014-0489Debian advanced package tool improper input validation vulnerabilityAPT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary co…EPSS 3.6%7.5CVE-2014-0490Debian advanced package tool improper input validation vulnerabilityThe apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitra…EPSS 3.6%6.8CVE-2014-0488Debian advanced package tool improper input validation vulnerabilityAPT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to h…EPSS 2.1%6.8CVE-2014-6273Debian advanced package tool memory buffer overflow vulnerabilityBuffer overflow in the HTTP transport code in apt-get in APT 1.0.1 and earlier allows man-in-the-middle attackers to cause a denial of service (crash…EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2012-3587), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.