LWN.net Logo

ubuntuone-client: information leak

Package(s):ubuntuone-client CVE #(s):CVE-2011-4409
Created:June 6, 2012 Updated:June 13, 2012
Description: From the Ubuntu advisory:

It was discovered that the Ubuntu One Client incorrectly validated server certificates when using HTTPS connections. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to alter or compromise confidential information.

Alerts:
Ubuntu USN-1465-1 2012-06-06
Ubuntu USN-1465-2 2012-06-06
Ubuntu USN-1465-3 2012-06-06

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds