CVE-2011-4407: Input Validation
ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4407?
CVE-2011-4407 has been classified as a medium severity vulnerability affecting certain versions of Ubuntu Linux.
How do I fix CVE-2011-4407?
To fix CVE-2011-4407, update to Software Properties version 0.81.13.3 or later.
What type of vulnerability is CVE-2011-4407?
CVE-2011-4407 is a man-in-the-middle (MITM) vulnerability due to improper server certificate validation.
Which software versions are affected by CVE-2011-4407?
CVE-2011-4407 affects Ubuntu versions 10.04, 10.10, 11.04, and 11.10, along with Software Properties versions up to 0.81.13.1.
What impact does CVE-2011-4407 have on users?
Users affected by CVE-2011-4407 may be exposed to spoofed GPG keys for package repositories, leading to possible installation of malicious software.