|
|
| |
|
| |
software-properties: man-in-the-middle attack
| Package(s): | software-properties |
CVE #(s): | CVE-2011-4407
|
| Created: | January 31, 2012 |
Updated: | October 2, 2012 |
| Description: |
From the Ubuntu advisory:
David Black discovered that Software Properties incorrectly validated
server certificates when performing secure connections to download PPA GPG
key fingerprints. If a remote attacker were able to perform a
man-in-the-middle attack, this flaw could be exploited to install altered
package repository GPG keys. |
| Alerts: |
|
( Log in to post comments)
|
|
|