First published: Tue Nov 29 2011(Updated: )
Software Center in Ubuntu 11.10, 11.04 10.10 does not properly validate server certificates, which allows remote attackers to execute arbitrary code or obtain sensitive information via a man-in-the-middle (MITM) attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu Linux | =10.10 | |
Ubuntu Linux | =11.04 | |
Ubuntu Linux | =11.10 | |
Ubuntu | =10.10 | |
Ubuntu | =11.04 | |
Ubuntu | =11.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3150 is considered to be of medium severity due to the potential for remote code execution and information leakage.
To fix CVE-2011-3150, upgrade to a version of Ubuntu that has patched the vulnerability, such as Ubuntu 12.04 or later.
CVE-2011-3150 affects Ubuntu versions 10.10, 11.04, and 11.10.
CVE-2011-3150 can be exploited through man-in-the-middle attacks due to improper validation of server certificates.
Yes, there are documented exploit methods that leverage the man-in-the-middle vulnerability associated with CVE-2011-3150.