Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Ubuntu 11.04 USN-1270-1 Critical: Software Center Installation Flaw

Ubuntu Large Esm H500
An attacker could trick Software Center into installing altered packages and repositories or exposing sensitive information over the network.
=========================================================================Ubuntu Security Notice USN-1270-1
November 21, 2011

software-center vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.10

Summary:

An attacker could trick Software Center into installing altered packages
and repositories or exposing sensitive information over the network.

Software Description:
- software-center: Utility for browsing, installing, and removing software

Details:

David B. discovered that Software Center incorrectly validated server
certificates when performing secure connections. If a remote attacker were
able to perform a man-in-the-middle attack, this flaw could be exploited to
view sensitive information or install altered packages and repositories.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  software-center                 5.0.2ubuntu0.1

Ubuntu 11.04:
  software-center                 4.0.5ubuntu0.1

Ubuntu 10.10:
  software-center                 3.0.10ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-1270-1
  CVE-2011-3150

Package Information:
  https://launchpad.net/ubuntu/+source/software-center/5.0.2ubuntu0.1
  https://launchpad.net/ubuntu/+source/software-center/4.0.5ubuntu0.1
  https://launchpad.net/ubuntu/+source/software-center/3.0.10ubuntu0.1


Ubuntu 11.04 USN-1270-1 Critical: Software Center Installation Flaw

ubuntu
Calendar Grey November 21, 2011
Dist Ubuntu Esm H88
Critical security flaw in Ubuntu Software Center allows unauthorized installations and data exposure: USN-1270-1.
An attacker could trick Software Center into installing altered packages and repositories or exposing sensitive information over the network.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: software-center 5.0.2ubuntu0.1 Ubuntu 11.04: software-center 4.0.5ubuntu0.1 Ubuntu 10.10: software-center 3.0.10ubuntu0.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1270-1

CVE-2011-3150

Severity
critical
Lowest
Low
Medium
High
Critical

November 21, 2011

Package Information

https://launchpad.net/ubuntu/+source/software-center/5.0.2ubuntu0.1 https://launchpad.net/ubuntu/+source/software-center/4.0.5ubuntu0.1 https://launchpad.net/ubuntu/+source/software-center/3.0.10ubuntu0.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here