CVE-2011-4408
published 2012-06-16CVE-2011-4408: The Single Sign On Client (ubuntu-sso-client) for Ubuntu 11.04 and 11.10 does not properly validate SSL certificates when using HTTPS, which allows remote…
PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.24%
66.3th percentile
The Single Sign On Client (ubuntu-sso-client) for Ubuntu 11.04 and 11.10 does not properly validate SSL certificates when using HTTPS, which allows remote attackers to spoof a server and modify or read sensitive data via a man-in-the-middle (MITM) attack.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c4ch-35xg-vqch: The Single Sign On Client (ubuntu-sso-client) for Ubuntu 11
ghsa_unreviewed·2022-05-17
CVE-2011-4408 [MEDIUM] GHSA-c4ch-35xg-vqch: The Single Sign On Client (ubuntu-sso-client) for Ubuntu 11
The Single Sign On Client (ubuntu-sso-client) for Ubuntu 11.04 and 11.10 does not properly validate SSL certificates when using HTTPS, which allows remote attackers to spoof a server and modify or read sensitive data via a man-in-the-middle (MITM) attack.
Ubuntu
Ubuntu Single Sign On Client vulnerability
vendor_ubuntu·2012-06-06
CVE-2011-4408 Ubuntu Single Sign On Client vulnerability
Title: Ubuntu Single Sign On Client vulnerability
Summary: Fraudulent security certificates could allow sensitive information to
be exposed when accessing the Internet.
It was discovered that the Ubuntu Single Sign On Client incorrectly
validated server certificates when using HTTPS connections. If a remote
attacker were able to perform a machine-in-the-middle attack, this flaw could
be exploited to alter or compromise confidential information.
Instructions: In general, a standard system update will make all the necessary changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/82747http://secunia.com/advisories/49448http://www.securityfocus.com/bid/53829http://www.ubuntu.com/usn/USN-1464-1https://exchange.xforce.ibmcloud.com/vulnerabilities/76112http://osvdb.org/82747http://secunia.com/advisories/49448http://www.securityfocus.com/bid/53829http://www.ubuntu.com/usn/USN-1464-1https://exchange.xforce.ibmcloud.com/vulnerabilities/76112
2012-06-16
Published