CVE-2020-15709

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-15709
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-15709.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-15709
Related
Published
2020-09-05T04:15:13Z
Modified
2024-10-22T16:45:32.286817Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Versions of add-apt-repository before 0.98.9.2, 0.96.24.32.14, 0.96.20.10, and 0.92.37.8ubuntu0.1~esm1, printed a PPA (personal package archive) description to the terminal as-is, which allowed PPA owners to provide ANSI terminal escapes to modify terminal contents in unexpected ways.

References

Affected packages

Debian:11 / software-properties

Package

Name
software-properties
Purl
pkg:deb/debian/software-properties?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.96.20.2-2.1
0.96.24.32.7-1
0.99.30-1
0.99.30-2
0.99.30-2.1
0.99.30-2.2
0.99.30-3
0.99.30-4
0.99.30-4.1~deb12u1
0.99.30-4.1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / software-properties

Package

Name
software-properties
Purl
pkg:deb/debian/software-properties?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.99.30-4
0.99.30-4.1~deb12u1
0.99.30-4.1

Ecosystem specific

{
    "urgency": "unimportant"
}