Login
Newsletter
Werbung

Sicherheit: Mangelnde Prüfung von Zertifikaten in Ubuntu One Client
Aktuelle Meldungen Distributionen
Name: Mangelnde Prüfung von Zertifikaten in Ubuntu One Client
ID: USN-1465-2
Distribution: Ubuntu
Plattformen: Ubuntu 10.04 LTS, Ubuntu 11.04, Ubuntu 11.10, Ubuntu 12.04 LTS
Datum: Mi, 6. Juni 2012, 17:37
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4409
Applikationen: Ubuntu One Client

Originalnachricht


--===============8986057563574845174==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-jcQi9ZAjB+Kyd4l0FHOb"


--=-jcQi9ZAjB+Kyd4l0FHOb
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1465-2
June 06, 2012

ubuntuone-storage-protocol update
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS

Summary:

Fraudulent security certificates could allow sensitive information to
be exposed when accessing the Internet.

Software Description:
- ubuntuone-storage-protocol: Python library for Ubuntu One file storage and
sharing service

Details:

USN-1465-1 fixed a vulnerability in the Ubuntu One Client. This update adds
a required fix to the Ubuntu One storage protocol library.

Original advisory details:

It was discovered that the Ubuntu One Client incorrectly validated server
certificates when using HTTPS connections. If a remote attacker were able
to perform a man-in-the-middle attack, this flaw could be exploited to
alter or compromise confidential information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
python-ubuntuone-storageprotocol 3.0.0-0ubuntu1.1

Ubuntu 11.10:
python-ubuntuone-storageprotocol 2.0.1-0ubuntu1.1

Ubuntu 11.04:
python-ubuntuone-storageprotocol 1.6.1-0ubuntu1.2

Ubuntu 10.04 LTS:
python-ubuntuone-storageprotocol 1.2.0-0ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1465-2
http://www.ubuntu.com/usn/usn-1465-1
CVE-2011-4409

Package Information:
https://launchpad.net/ubuntu/+source/ubuntuone-storage-protocol/3.0.0-0ubuntu1.1
https://launchpad.net/ubuntu/+source/ubuntuone-storage-protocol/2.0.1-0ubuntu1.1
https://launchpad.net/ubuntu/+source/ubuntuone-storage-protocol/1.6.1-0ubuntu1.2
https://launchpad.net/ubuntu/+source/ubuntuone-storage-protocol/1.2.0-0ubuntu1.1



--ÓcQi9ZAjB+Kyd4l0FHOb
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJPz2AmAAoJEGVp2FWnRL6T4+AP/ikx99qE5LL+4lO5UGxnJDHG
0qrnKD8i4H+AcsIcwFBeXZQUw+uGTbRpuSHFeiPutNPeLpi1zW+Os9dscusbUhxZ
YO/B6hbZAdZbqTcedN7fmW9m9P3SjJ/pmmri5pLV/uAZPhktxGCv66OlDoezBab5
Oabsy6iZmWZLqfbhN8SU4bJjoC1dYC4Vb3U3eQJqFgfdYxswzBxp1+wZ3H5wxLV4
kpxJRggPVIkBGHZwPEnwRLARIx2rk0X4sct6SXaafzbYKCic+X3bb7721FXxi8EP
dhM+1960UnP0hBRAQYPKuIUgVQD3fpTSeceNmG1ObkHnBbxiX8DsoQPOan1pqWdy
AfDZWd0+iqQCrXF0WWYcDCO/wPNPa2iQVxsZQKBg7Rauallyq4PsX4g4m1Go6Ffb
dEMs8mBP0yOMNiTSra5UszneWSZnjFq5f9kqy0sRkUg2kB0TdGERydcGislAbrA+
BT2XodwL23raSn3sGNPAB2zneuQEL7wUtn3zxT4Oy3+fCukGjQIkfsDFZ8SJZbED
9oDOvLksnw6HJzAXkwjy4vKD/dmAnWdX99WTxvCVH2YL9nBqtWTYSl0zsiU32WsR
N3R9Xbz0q8+OmVH/cWRreeGbCMOiaD3Wl9LvJbZDvWTPYlJLvkaTVnzxNEAsGl+F
ePfy5BiYxri5sUhn2wdS
=X3po
-----END PGP SIGNATURE-----

--=-jcQi9ZAjB+Kyd4l0FHOb--



--===============8986057563574845174==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============8986057563574845174==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung