Login
Newsletter
Werbung

Sicherheit: Mangelnde Prüfung von Zertifikaten in Ubuntu One CouchDB
Aktuelle Meldungen Distributionen
Name: Mangelnde Prüfung von Zertifikaten in Ubuntu One CouchDB
ID: USN-1381-1
Distribution: Ubuntu
Plattformen: Ubuntu 11.10
Datum: Do, 1. März 2012, 17:31
Referenzen: Keine Angabe
Applikationen: Ubuntu One CouchDB

Originalnachricht


--===============1753818706083253131==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-tdUWI+UfLPrJUktlG/z1"


--=-tdUWI+UfLPrJUktlG/z1
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1381-1
March 01, 2012

ubuntuone-couch vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.10

Summary:

Fraudulent security certificates could allow sensitive information to
be exposed when accessing the Internet.

Software Description:
- ubuntuone-couch: Ubuntu One CouchDB

Details:

It was discovered that Ubuntu One Couch did not perform any server
certificate validation when using HTTPS connections. If a remote attacker
were able to perform a man-in-the-middle attack, this flaw could be
exploited to alter or compromise confidential information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
ubuntuone-couch 0.3.0-0ubuntu2.1

After a standard system update you need to restart your session to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1381-1
https://launchpad.net/bugs/882049

Package Information:
https://launchpad.net/ubuntu/+source/ubuntuone-couch/0.3.0-0ubuntu2.1



--ÝdUWI+UfLPrJUktlG/z1
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJPT5kfAAoJEGVp2FWnRL6T7B4P/RJdKLE/vZfG2LY8pnewyGMj
gBXLv6hpH4PA+/+RC9IR8raxTnWxgYUGcLW/wayKsdVg3pof2ZNbbAm8eZbsoVXU
pDXKjSN8CngayVD1ZGZQfDPSey8PW0BGeT7uerOR1BtXF3L0R+0NO78YgN0WeoZQ
SFl+nROszr1B7E+WH+qcLGxOjY7XB+QFg/wQWh3r9eOSnu1RTzIJyPMt/PFngNOT
V/FNUEe9qo0A09vG5tcM/We4d7oDCBezfOisOc7Mxm+HBdhUs2Ta+1r6U+cV1dLB
yJWvFBNAjhgBpqjsmI+202OT0uznFADOCR7gu+LTn7MwizN/ZdPJCd9G7bniyejd
E2yOUZMda8wITaDZX/K1x964cRROnPgonrUjX9kOJJjefM44gWekqBiw+FUdrmDd
46Z2P4O+plsb6YB2cigkw3l1NgEASjEXTfxsbkaNgQjRPqXt2jyUxCNnLTUc/Bks
5Grsim2pr12+iAowzSYB/RJZkCMWa0gr/feWpXng2UWqttunQ927t/SEz+qtUUFX
Tt5+YbifxRjucaM4Tq5aupJS4I65HC1EcW/bOlAUQRJu+EU7YQEL4kWr3JHWQgyX
vkLm8EJ4qQwkqNi3w4YxHK3U8qe13cgUQnCnV6DNSrna3VviEmpdjGX75THfMlSz
8wdYVOPkl3lAzgLXit93
=Mpqk
-----END PGP SIGNATURE-----

--=-tdUWI+UfLPrJUktlG/z1--



--===============1753818706083253131==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============1753818706083253131==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung