LWN.net Logo

update-manager: multiple vulnerabilities

Package(s):update-manager CVE #(s):CVE-2011-3152 CVE-2011-3154
Created:November 28, 2011 Updated:February 16, 2012
Description: From the Ubuntu advisory:

David Black discovered that Update Manager incorrectly extracted the downloaded upgrade tarball before verifying its GPG signature. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could potentially be used to replace arbitrary files. (CVE-2011-3152)

David Black discovered that Update Manager created a temporary directory in an insecure fashion. A local attacker could possibly use this flaw to read the XAUTHORITY file of the user performing the upgrade. (CVE-2011-3154)

Alerts:
Ubuntu USN-1284-1 2011-11-28
Ubuntu USN-1284-2 2012-02-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds