CVE-2020-15709

CVE-2020-15709: add-apt-repository print ASNI terminal codes

Vendor Canonical
Product add-apt-repository
Weakness CWE-20 · Input validation
Published September 5, 2020
Last update September 17, 2024

CVSS base score

What the vulnerability does

01Description

Versions of add-apt-repository before 0.98.9.2, 0.96.24.32.14, 0.96.20.10, and 0.92.37.8ubuntu0.1~esm1, printed a PPA (personal package archive) description to the terminal as-is, which allowed PPA owners to provide ANSI terminal escapes to modify terminal contents in unexpected ways.

Key dates

02Disclosure timeline

September 5, 2020 CVE published
September 17, 2024 Record updated