First published: Sat Jun 16 2012(Updated: )
The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate SSL certificates, which allows remote attackers to spoof a server and modify or read sensitive information via a man-in-the-middle (MITM) attack.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu | =11.04 | |
Ubuntu | =11.10 | |
Ubuntu | =12.04 | |
Ubuntu | =10.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4409 has a moderate severity level due to its potential for man-in-the-middle attacks.
To fix CVE-2011-4409, upgrade your Ubuntu One Client to a version that properly validates SSL certificates.
CVE-2011-4409 affects Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS.
CVE-2011-4409 can be exploited through man-in-the-middle (MITM) attacks, allowing unauthorized access to sensitive information.
No specific workarounds are recommended for CVE-2011-4409 other than updating to the latest secure version.