Ubuntu Update Manager GPG Signature Verification Security Bypass Vulnerability
BID:50833
Info
Ubuntu Update Manager GPG Signature Verification Security Bypass Vulnerability
| Bugtraq ID: | 50833 |
| Class: | Design Error |
| CVE: |
CVE-2011-3152 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2011 12:00AM |
| Updated: | Nov 28 2011 12:00AM |
| Credit: | David Black |
| Vulnerable: |
Ubuntu Update Manager 0 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 |
| Not Vulnerable: | |
Discussion
Ubuntu Update Manager GPG Signature Verification Security Bypass Vulnerability
Ubuntu Update Manager is prone to a signature-verification security-bypass vulnerability.
An attacker may exploit this issue through man-in-the-middle attacks. Successful attacks may allow the attacker to execute arbitrary code on a vulnerable computer.
Ubuntu Update Manager is prone to a signature-verification security-bypass vulnerability.
An attacker may exploit this issue through man-in-the-middle attacks. Successful attacks may allow the attacker to execute arbitrary code on a vulnerable computer.
Exploit / POC
Ubuntu Update Manager GPG Signature Verification Security Bypass Vulnerability
An attacker can exploit this issue by performing a man-in-the-middle attack.
An attacker can exploit this issue by performing a man-in-the-middle attack.
Solution / Fix
Ubuntu Update Manager GPG Signature Verification Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Ubuntu Update Manager GPG Signature Verification Security Bypass Vulnerability
References:
References:
- Ubuntu Homepage (Ubuntu)