cbcvebase.
CVE-2011-4407
published 2014-05-14

CVE-2011-4407: ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows…

PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.63%
46.1th percentile
ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.

Affected

8 ranges
VendorProductVersion rangeFixed in
canonicalsoftware-properties<= 0.81.13.1
canonicalsoftware-properties>= 0 < 0.76.7debian2+nmu20.76.7debian2+nmu2
canonicalsoftware-properties>= 0 < 0.76.7debian2+nmu20.76.7debian2+nmu2
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiansoftware-properties< software-properties 0.76.7debian2+nmu2 (bookworm)software-properties 0.76.7debian2+nmu2 (bookworm)

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.