LWN.net Logo

software-center: man-in-the-middle attack/information disclosure

Package(s):software-center CVE #(s):CVE-2011-3150
Created:November 21, 2011 Updated:November 23, 2011
Description: From the Ubuntu advisory:

David B. discovered that Software Center incorrectly validated server certificates when performing secure connections. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to view sensitive information or install altered packages and repositories.

Alerts:
Ubuntu USN-1270-1 2011-11-21

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds