CVE-2011-4409
published 2012-06-16CVE-2011-4409: The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate SSL certificates, which allows remote attackers to spoof a…
PriorityP337high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.75%
75.7th percentile
The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate SSL certificates, which allows remote attackers to spoof a server and modify or read sensitive information via a man-in-the-middle (MITM) attack.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ubuntu One Client vulnerability
vendor_ubuntu·2012-06-06
CVE-2011-4409 Ubuntu One Client vulnerability
Title: Ubuntu One Client vulnerability
Summary: Fraudulent security certificates could allow sensitive information to
be exposed when accessing the Internet.
It was discovered that the Ubuntu One Client incorrectly validated server
certificates when using HTTPS connections. If a remote attacker were able
to perform a machine-in-the-middle attack, this flaw could be exploited to
alter or compromise confidential information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Ubuntu One Client regression
vendor_ubuntu·2012-06-06
CVE-2011-4409 Ubuntu One Client regression
Title: Ubuntu One Client regression
Summary: Fraudulent security certificates could allow sensitive information to
be exposed when accessing the Internet.
USN-1465-1 fixed vulnerabilities in Ubuntu One Client. The update failed to
install on certain Ubuntu 10.04 LTS systems that had a legacy Python 2.5
package installed. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Ubuntu One Client incorrectly validated server
certificates when using HTTPS connections. If a remote attacker were able
to perform a machine-in-the-middle attack, this flaw could be exploited to
alter or compromise confidential information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Ubuntu One storage protocol update
vendor_ubuntu·2012-06-06
CVE-2011-4409 Ubuntu One storage protocol update
Title: Ubuntu One storage protocol update
Summary: Fraudulent security certificates could allow sensitive information to
be exposed when accessing the Internet.
USN-1465-1 fixed a vulnerability in the Ubuntu One Client. This update adds
a required fix to the Ubuntu One storage protocol library.
Original advisory details:
It was discovered that the Ubuntu One Client incorrectly validated server
certificates when using HTTPS connections. If a remote attacker were able
to perform a machine-in-the-middle attack, this flaw could be exploited to
alter or compromise confidential information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
php: NumberFormatter: set a symbol value crash (DoS) on bogus values
vendor_redhat·2010-12-07·CVSS 5.0
CVE-2011-1467 [MEDIUM] php: NumberFormatter: set a symbol value crash (DoS) on bogus values
php: NumberFormatter: set a symbol value crash (DoS) on bogus values
Unspecified vulnerability in the NumberFormatter::setSymbol (aka numfmt_set_symbol) function in the Intl extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via an invalid argument, a related issue to CVE-2010-4409.
Statement: This issue did not affect the versions of PHP as shipped with Red Hat Enterprise Linux 4 and 5. The getSymbol() and setSymbol() functions are unlikely to ever receive untrusted input as an $attr argument, and it is even less likely that they would receive such input when only a small set of pre-defined constants is expected. As a result, this flaw can only be triggered by the script author and cannot be used to cross trust boundaries. T
GHSA
GHSA-8m4g-h664-74qj: The Ubuntu One Client for Ubuntu 10
ghsa_unreviewed·2022-05-17
CVE-2011-4409 [HIGH] CWE-20 GHSA-8m4g-h664-74qj: The Ubuntu One Client for Ubuntu 10
The Ubuntu One Client for Ubuntu 10.04 LTS, 11.04, 11.10, and 12.04 LTS does not properly validate SSL certificates, which allows remote attackers to spoof a server and modify or read sensitive information via a man-in-the-middle (MITM) attack.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/49442http://ubuntu.com/usn/usn-1465-1http://ubuntu.com/usn/usn-1465-2http://ubuntu.com/usn/usn-1465-3http://www.osvdb.org/82748http://www.securityfocus.com/bid/53828https://exchange.xforce.ibmcloud.com/vulnerabilities/76113http://secunia.com/advisories/49442http://ubuntu.com/usn/usn-1465-1http://ubuntu.com/usn/usn-1465-2http://ubuntu.com/usn/usn-1465-3http://www.osvdb.org/82748http://www.securityfocus.com/bid/53828https://exchange.xforce.ibmcloud.com/vulnerabilities/76113
2012-06-16
Published