|
|
| |
|
| |
ubuntu-sso-client: information leak
| Package(s): | ubuntu-sso-client |
CVE #(s): | CVE-2011-4408
|
| Created: | June 6, 2012 |
Updated: | June 13, 2012 |
| Description: |
From the Ubuntu advisory:
It was discovered that the Ubuntu Single Sign On Client incorrectly
validated server certificates when using HTTPS connections. If a remote
attacker were able to perform a man-in-the-middle attack, this flaw could
be exploited to alter or compromise confidential information. |
| Alerts: |
|
( Log in to post comments)
|
|
|