Login
Newsletter
Werbung

Sicherheit: Mangelnde Prüfung von Zertifikaten in Software Center
Aktuelle Meldungen Distributionen
Name: Mangelnde Prüfung von Zertifikaten in Software Center
ID: USN-1270-1
Distribution: Ubuntu
Plattformen: Ubuntu 10.10, Ubuntu 11.04, Ubuntu 11.10
Datum: Mo, 21. November 2011, 22:34
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3150
Applikationen: Software Center

Originalnachricht


--===============2178826668144996423==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-RNLhvwoFZeOQu3Ab6dhp"


--=-RNLhvwoFZeOQu3Ab6dhp
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1270-1
November 21, 2011

software-center vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.10

Summary:

An attacker could trick Software Center into installing altered packages
and repositories or exposing sensitive information over the network.

Software Description:
- software-center: Utility for browsing, installing, and removing software

Details:

David B. discovered that Software Center incorrectly validated server
certificates when performing secure connections. If a remote attacker were
able to perform a man-in-the-middle attack, this flaw could be exploited to
view sensitive information or install altered packages and repositories.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
software-center 5.0.2ubuntu0.1

Ubuntu 11.04:
software-center 4.0.5ubuntu0.1

Ubuntu 10.10:
software-center 3.0.10ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1270-1
CVE-2011-3150

Package Information:
https://launchpad.net/ubuntu/+source/software-center/5.0.2ubuntu0.1
https://launchpad.net/ubuntu/+source/software-center/4.0.5ubuntu0.1
https://launchpad.net/ubuntu/+source/software-center/3.0.10ubuntu0.1



--ÛNLhvwoFZeOQu3Ab6dhp
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJOypelAAoJEGVp2FWnRL6TPTYP/iDsLZHFyY9HcEbfKAuZAneD
kyJTbKiU22AoFSYxtYDAOweihY3K2boILOsdrC53SJEgaCQqTlltXk/Urk5/qhNC
lSAz6XaiJcB8DXR4g2vG4KuGghNGxryM8DtMPq1cNEbkWIvsBCLVN8c5xcSq6ovL
z0MUn3swp0L6jQMVkte49w1X+8XRyZaOdUviXZPTPoJHw+OaFjDgLkg48VZg7Hoi
TyH/BLtS0qS4jsqX2ZobRreG4o/qXUxXOjeaXBH4kP5GF+YL/Kl8VMHVoyuaBBXR
6AktNbuVCwITpRjGlu4E5f5ujWGGOKCC/MhR+SQMkmYpLjCjbFmDWiBVldlWtv6C
5LG+2K5Ve1Pt1sZLiOqjlLcNARCP3pZYzjpyrouyulLkUeouDl+5T28KmJqIhczg
VV5SAeNQpYV+JTQMIZfLQWdoidaYFHRRFKXuIXGtkmCdmNTEFG2TCFuOH/q35/BF
nCfCLZU8Imuh8chF/t0tCIqlpnI40QKyjBntcC3Oakz3f8TmBa52g8MBC035yoJT
ovUYxTEi1mlBviHCCyN+WPr5N9W4RiSFJVr4fUSvdr2JiILLfEHEk6Q1/Xu/P+j+
kmDye8bTL+CzTI1/c48nd8sHtwrprYkyiIJVKwBHVfQLpbv/WSogLhVPkvA4TfPI
hbC7oLAl8bNt4R/9r/LK
=BQfE
-----END PGP SIGNATURE-----

--=-RNLhvwoFZeOQu3Ab6dhp--



--===============2178826668144996423==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============2178826668144996423==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung