CVE-2011-4407
14.05.2014, 00:55
ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.Enginsight
Vendor | Product | Version |
---|---|---|
canonical | software-properties | 𝑥 ≤ 0.81.13.1 |
canonical | ubuntu_linux | 10.04 |
canonical | ubuntu_linux | 10.10 |
canonical | ubuntu_linux | 11.04 |
canonical | ubuntu_linux | 11.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration