CVE-2011-3150
published 2011-11-29CVE-2011-3150: Software Center in Ubuntu 11.10, 11.04 10.10 does not properly validate server certificates, which allows remote attackers to execute arbitrary code or obtain…
PriorityP434medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.90%
77.7th percentile
Software Center in Ubuntu 11.10, 11.04 10.10 does not properly validate server certificates, which allows remote attackers to execute arbitrary code or obtain sensitive information via a man-in-the-middle (MITM) attack.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5j3j-rq5g-q8c8: Software Center in Ubuntu 11
ghsa_unreviewed·2022-05-17
CVE-2011-3150 [MEDIUM] CWE-20 GHSA-5j3j-rq5g-q8c8: Software Center in Ubuntu 11
Software Center in Ubuntu 11.10, 11.04 10.10 does not properly validate server certificates, which allows remote attackers to execute arbitrary code or obtain sensitive information via a man-in-the-middle (MITM) attack.
Ubuntu
Software Center vulnerability
vendor_ubuntu·2011-11-21
CVE-2011-3150 Software Center vulnerability
Title: Software Center vulnerability
Summary: An attacker could trick Software Center into installing altered packages
and repositories or exposing sensitive information over the network.
David B. discovered that Software Center incorrectly validated server
certificates when performing secure connections. If a remote attacker were
able to perform a machine-in-the-middle attack, this flaw could be exploited to
view sensitive information or install altered packages and repositories.
Instructions: In general, a standard system update will make all the necessary changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/46950http://www.securityfocus.com/bid/50754http://www.ubuntu.com/usn/USN-1270-1https://exchange.xforce.ibmcloud.com/vulnerabilities/71430http://secunia.com/advisories/46950http://www.securityfocus.com/bid/50754http://www.ubuntu.com/usn/USN-1270-1https://exchange.xforce.ibmcloud.com/vulnerabilities/71430
2011-11-29
Published