Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-3152

Опубликовано: 27 апр. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.4

Описание

DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 on Ubuntu 8.04 through 11.10 does not verify the GPG signature before extracting an upgrade tarball, which allows man-in-the-middle attackers to (1) create or overwrite arbitrary files via a directory traversal attack using a crafted tar file, or (2) bypass authentication via a crafted meta-release file.

РелизСтатусПримечание
devel

released

1:0.154.5
hardy

released

1:0.87.31.1
lucid

released

1:0.134.11.1
maverick

released

1:0.142.23.1
natty

released

1:0.150.5.1
oneiric

released

1:0.152.25.5
upstream

needs-triage

Показывать по

EPSS

Процентиль: 60%
0.00404
Низкий

6.4 Medium

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 on Ubuntu 8.04 through 11.10 does not verify the GPG signature before extracting an upgrade tarball, which allows man-in-the-middle attackers to (1) create or overwrite arbitrary files via a directory traversal attack using a crafted tar file, or (2) bypass authentication via a crafted meta-release file.

debian
почти 12 лет назад

DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87. ...

github
больше 3 лет назад

DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 on Ubuntu 8.04 through 11.10 does not verify the GPG signature before extracting an upgrade tarball, which allows man-in-the-middle attackers to (1) create or overwrite arbitrary files via a directory traversal attack using a crafted tar file, or (2) bypass authentication via a crafted meta-release file.

EPSS

Процентиль: 60%
0.00404
Низкий

6.4 Medium

CVSS2