LWN.net Logo

ubunutone-couch: certificate validation flaw

Package(s):ubuntuone-couch CVE #(s):
Created:March 1, 2012 Updated:March 7, 2012
Description:

From the Ubuntu advisory:

It was discovered that Ubuntu One Couch did not perform any server certificate validation when using HTTPS connections. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to alter or compromise confidential information.

Alerts:
Ubuntu USN-1381-1 2012-03-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds