CVE-2011-4407
published 2014-05-14CVE-2011-4407: ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.63%
46.1th percentile
ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | software-properties | <= 0.81.13.1 | — |
| canonical | software-properties | >= 0 < 0.76.7debian2+nmu2 | 0.76.7debian2+nmu2 |
| canonical | software-properties | >= 0 < 0.76.7debian2+nmu2 | 0.76.7debian2+nmu2 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | software-properties | < software-properties 0.76.7debian2+nmu2 (bookworm) | software-properties 0.76.7debian2+nmu2 (bookworm) |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m49h-wwcv-rf5m: ppa
ghsa_unreviewed·2022-05-17
CVE-2011-4407 [MEDIUM] CWE-20 GHSA-m49h-wwcv-rf5m: ppa
ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.
OSV
CVE-2011-4407: ppa
osv·2014-05-14·CVSS 4.3
CVE-2011-4407 [MEDIUM] CVE-2011-4407: ppa
ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.
Ubuntu
Software Properties vulnerability
vendor_ubuntu·2012-01-31
CVE-2011-4407 Software Properties vulnerability
Title: Software Properties vulnerability
Summary: Software Properties could be tricked into installing arbitrary PPA GPG
keys.
David Black discovered that Software Properties incorrectly validated
server certificates when performing secure connections to download PPA GPG
key fingerprints. If a remote attacker were able to perform a
machine-in-the-middle attack, this flaw could be exploited to install altered
package repository GPG keys.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2011-4407: software-properties - ppa.py in Software Properties before 0.81.13.3 does not validate the server cert...
vendor_debian·2011·CVSS 4.3
CVE-2011-4407 [MEDIUM] CVE-2011-4407: software-properties - ppa.py in Software Properties before 0.81.13.3 does not validate the server cert...
ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.
Scope: local
bookworm: resolved (fixed in 0.76.7debian2+nmu2)
bullseye: resolved (fixed in 0.76.7debian2+nmu2)
sid: resolved (fixed in 0.76.7debian2+nmu2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-05-14
Published