The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate SSL certificates, which allows remote attackers to spoof a server and modify or read sensitive information via a man-in-the-middle (MITM) attack.
References
Link | Resource |
---|---|
http://ubuntu.com/usn/usn-1465-2 | Vendor Advisory |
http://www.osvdb.org/82748 | |
http://www.securityfocus.com/bid/53828 | |
http://ubuntu.com/usn/usn-1465-1 | Vendor Advisory |
http://secunia.com/advisories/49442 | Vendor Advisory |
http://ubuntu.com/usn/usn-1465-3 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/76113 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2012-06-15 17:55
Updated : 2017-08-28 18:30
NVD link : CVE-2011-4409
Mitre link : CVE-2011-4409
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
canonical
- ubuntu_linux