Описание
The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate SSL certificates, which allows remote attackers to spoof a server and modify or read sensitive information via a man-in-the-middle (MITM) attack.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 3.99.0-0ubuntu1 |
| hardy | DNE | |
| lucid | released | 1.2.2-0ubuntu2.2 |
| natty | released | 1.6.2-0ubuntu2.1 |
| oneiric | released | 2.0.1-0ubuntu1.1 |
| precise | released | 3.0.0-0ubuntu1.1 |
| upstream | needs-triage |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 3.99.0-0ubuntu1 |
| hardy | DNE | |
| lucid | released | 1.2.0-0ubuntu1.1 |
| natty | released | 1.6.1-0ubuntu1.2 |
| oneiric | released | 2.0.1-0ubuntu1.1 |
| precise | released | 3.0.0-0ubuntu1.1 |
| upstream | needs-triage |
Показывать по
7.5 High
CVSS2
Связанные уязвимости
The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate SSL certificates, which allows remote attackers to spoof a server and modify or read sensitive information via a man-in-the-middle (MITM) attack.
The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate SSL certificates, which allows remote attackers to spoof a server and modify or read sensitive information via a man-in-the-middle (MITM) attack.
7.5 High
CVSS2