First published: Mon Aug 09 2010(Updated: )
The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote archive servers and man-in-the-middle attackers to execute arbitrary code via a crafted package.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu Linux | =9.10 | |
Ubuntu Linux | =10.04 | |
Dell Latitude 2110 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-0834 is classified as high due to the lack of authentication for package installation.
To fix CVE-2010-0834, update the base-files package to versions 5.0.0ubuntu7.1 or later for Ubuntu 9.10 and 5.0.0ubuntu20.10.04.2 or later for Ubuntu 10.04 LTS.
CVE-2010-0834 affects Ubuntu 9.10 and Ubuntu 10.04 LTS if the base-files package is below the specified fixed versions.
Yes, CVE-2010-0834 can be exploited remotely by attackers using man-in-the-middle tactics due to the lack of authentication.
The Dell Latitude 2110 netbook, running affected versions of Ubuntu, is specifically noted to be vulnerable to CVE-2010-0834.