ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.
| Software | From | Fixed in |
|---|---|---|
| canonical / ubuntu_linux | 10.10 | 10.10.x |
| canonical / software-properties | - | 0.81.13.1.x |
| canonical / ubuntu_linux | 11.04 | 11.04.x |
| canonical / ubuntu_linux | 11.10 | 11.10.x |
| canonical / ubuntu_linux | 10.04 | 10.04.x |